Junglewise Threat Intelligence

CVE-2025-71395: SurrealDB memory exhaustion in string::replace function

CVE-2025-71395 · Severity: medium · CVSS 4 · Published 2026-07-18

Vendors: SurrealDB.

Executive brief

SurrealDB is a multi-model database used for managing and querying large-scale data. A vulnerability in its string processing functions allows a logged-in user to crash the database server by running a specially crafted search-and-replace command. This results in a total service outage, preventing all users and applications from accessing the database until it is restarted.

Technical details

A memory exhaustion vulnerability (CWE-789) exists in SurrealDB's 'string::replace' function when processing regular expressions. The root cause is a failure to enforce limits on the length of the resulting string during regex-based replacement operations. An authenticated attacker with network access can execute a malicious SurrealQL query that triggers unbounded memory allocations. This leads to a crash of the SurrealDB instance due to Out-Of-Memory (OOM) conditions. The issue has been patched in versions 2.0.5, 2.1.5, and 2.2.2 by introducing the 'SURREAL_GENERATION_ALLOCATION_LIMIT' to enforce string length constraints.

Affected products

  • SurrealDB SurrealDB < 2.0.5, < 2.1.5, < 2.2.2

Timeline

  • 2025-04-10: advisory: GitHub Security Advisory published
  • 2026-07-18: disclosed: NVD publication date

References