Executive brief
SurrealDB is a multi-model database used for managing and querying large-scale data. A vulnerability in its string processing functions allows a logged-in user to crash the database server by running a specially crafted search-and-replace command. This results in a total service outage, preventing all users and applications from accessing the database until it is restarted.
Technical details
A memory exhaustion vulnerability (CWE-789) exists in SurrealDB's 'string::replace' function when processing regular expressions. The root cause is a failure to enforce limits on the length of the resulting string during regex-based replacement operations. An authenticated attacker with network access can execute a malicious SurrealQL query that triggers unbounded memory allocations. This leads to a crash of the SurrealDB instance due to Out-Of-Memory (OOM) conditions. The issue has been patched in versions 2.0.5, 2.1.5, and 2.2.2 by introducing the 'SURREAL_GENERATION_ALLOCATION_LIMIT' to enforce string length constraints.
Affected products
- SurrealDB SurrealDB < 2.0.5, < 2.1.5, < 2.2.2
Timeline
- 2025-04-10: advisory: GitHub Security Advisory published
- 2026-07-18: disclosed: NVD publication date