Loading market data...
← Back to CVE feed

CVE-2026-63760

HIGH CVSS 7.5 View on NVD ↗

Description

SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated attackers can send deeply nested JSON payloads to the WebSocket /rpc endpoint to exhaust server memory and crash the process.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published: Jul 20, 2026 12:19 UTC Modified: Jul 20, 2026 13:16 UTC