Executive brief
SurrealDB is a multi-model database that allows users to run custom logic using embedded JavaScript. A vulnerability exists where these scripts do not have a maximum execution time limit, allowing a user to run complex code that never finishes. An attacker with database access could use this to consume all available server processing power, causing the database to become unresponsive or crash.
Technical details
SurrealDB versions prior to 2.0.5, 2.1.5, and 2.2.2 contain a resource exhaustion vulnerability (CWE-770) in the embedded JavaScript scripting engine. While the engine enforces memory and stack limits, it lacks a default execution-time timeout. An authenticated attacker can exploit this by submitting long-running or infinite-loop JavaScript functions if scripting is explicitly enabled (via --allow-scripting or --allow-all). This leads to CPU exhaustion and a Denial of Service (DoS) condition. The issue has been resolved by implementing a default timeout and a configurable SURREAL_SCRIPTING_MAX_TIME_LIMIT environment variable.
Affected products
- SurrealDB SurrealDB < 2.0.5, 2.1.x < 2.1.5, 2.2.x < 2.2.2
Timeline
- 2025-04-10: advisory: GitHub Security Advisory published
- 2026-07-18: disclosed: NVD publication date