Junglewise Threat Intelligence

CVE-2025-71396: SurrealDB denial of service via embedded JavaScript scripting

CVE-2025-71396 · Severity: medium · CVSS 4 · Published 2026-07-18

Vendors: SurrealDB.

Executive brief

SurrealDB is a multi-model database that allows users to run custom logic using embedded JavaScript. A vulnerability exists where these scripts do not have a maximum execution time limit, allowing a user to run complex code that never finishes. An attacker with database access could use this to consume all available server processing power, causing the database to become unresponsive or crash.

Technical details

SurrealDB versions prior to 2.0.5, 2.1.5, and 2.2.2 contain a resource exhaustion vulnerability (CWE-770) in the embedded JavaScript scripting engine. While the engine enforces memory and stack limits, it lacks a default execution-time timeout. An authenticated attacker can exploit this by submitting long-running or infinite-loop JavaScript functions if scripting is explicitly enabled (via --allow-scripting or --allow-all). This leads to CPU exhaustion and a Denial of Service (DoS) condition. The issue has been resolved by implementing a default timeout and a configurable SURREAL_SCRIPTING_MAX_TIME_LIMIT environment variable.

Affected products

  • SurrealDB SurrealDB < 2.0.5, 2.1.x < 2.1.5, 2.2.x < 2.2.2

Timeline

  • 2025-04-10: advisory: GitHub Security Advisory published
  • 2026-07-18: disclosed: NVD publication date

References