Junglewise Threat Intelligence

CVE-2024-58370: SurrealDB uncontrolled recursion in SurrealQL parser

CVE-2024-58370 · Severity: medium · CVSS 6.5 · Published 2026-07-18

Technologies: surrealdb (crates.io). Vendors: SurrealDB, crates.io.

Executive brief

SurrealDB is a multi-model database used for managing complex data structures. A vulnerability in its query processing engine allows an authorized user to crash the database server by sending a specially crafted, deeply nested query. This results in a denial-of-service (DoS) condition, making the database unavailable for all users and applications until it is restarted.

Technical details

The SurrealQL parser in SurrealDB fails to properly enforce recursion depth limits (such as those defined by the SURREAL_MAX_COMPUTATION_DEPTH environment variable) when processing specific nested statements, including IF, RELATE, and certain attribute access idioms. This vulnerability is classified as uncontrolled recursion (CWE-674). An attacker with network access and valid low-privilege credentials can submit a query with excessive nesting depth to trigger a stack overflow. This leads to an immediate crash of the database process, resulting in a denial of service. The issue was identified via OSS-Fuzz and is resolved in version 1.1.0.

Affected products

  • SurrealDB SurrealDB < 1.1.0

Timeline

  • 2024-01-17: advisory: Initial GitHub Security Advisory published
  • 2026-07-18: disclosed: NVD publication and CVE assignment

References

Related threats