Executive brief
SurrealDB is a multi-model database used for managing and querying data. A vulnerability in its query processing engine allows an authenticated user to crash the database server by sending a specially crafted query with deeply nested data types. This results in a denial-of-service (DoS) condition, disrupting database availability and any applications relying on it.
Technical details
An uncontrolled recursion vulnerability (CWE-674) exists in the SurrealDB type/kind parser. While the expression parser previously implemented recursion limits, the kind parser omitted these checks for nested type annotations (e.g., deeply nested array or option types). An authenticated attacker with query execution privileges can exploit this by sending a single WebSocket message containing deeply nested annotations, causing the server to exhaust memory and crash. This issue is an incomplete fix for a previous vulnerability (GHSA-6r8p-hpg7-825g). The vulnerability is resolved in version 3.1.0 by applying recursion depth limits to the 'parse_concrete_kind' and 'parse_inner_kind' functions.
Affected products
- SurrealDB SurrealDB < 3.1.0
Timeline
- 2026-05-27: advisory: Initial GitHub Security Advisory published
- 2026-07-20: disclosed: CVE-2026-63759 published to NVD
- 2026-07-20: patched: Fix released in version 3.1.0