Junglewise Threat Intelligence

CVE-2026-63762: SurrealDB denial of service in JavaScript scripting engine

CVE-2026-63762 · Severity: medium · CVSS 4 · Published 2026-07-20

Vendors: SurrealDB.

Executive brief

SurrealDB is a multi-model database used for managing and querying application data. A vulnerability in its optional JavaScript scripting engine allows an attacker to crash the database server by sending a specially crafted query. This results in an immediate service outage that requires a manual restart to restore operations.

Technical details

A NULL pointer dereference exists in the QuickJS-NG engine used by SurrealDB's embedded JavaScript runtime. The vulnerability is reachable when the --allow-scripting flag is enabled. An attacker with query execution privileges (which may include unauthenticated guests if --allow-guests is active) can use built-in string functions to construct an oversized string. When this string is passed to the JavaScript runtime for compilation, it triggers a crash in the underlying rquickjs dependency (v0.9.0). The issue was resolved by updating rquickjs to v0.11.0. Administrators can mitigate the risk by using the --deny-scripting flag.

Affected products

  • SurrealDB SurrealDB < v2.6.1, < v3.0.0-beta.3

Timeline

  • 2026-02-12: advisory: GitHub Security Advisory published
  • 2026-07-20: disclosed: NVD publication date

References