Executive brief
SurrealDB is a multi-model database used for managing and querying application data. A vulnerability in its optional JavaScript scripting engine allows an attacker to crash the database server by sending a specially crafted query. This results in an immediate service outage that requires a manual restart to restore operations.
Technical details
A NULL pointer dereference exists in the QuickJS-NG engine used by SurrealDB's embedded JavaScript runtime. The vulnerability is reachable when the --allow-scripting flag is enabled. An attacker with query execution privileges (which may include unauthenticated guests if --allow-guests is active) can use built-in string functions to construct an oversized string. When this string is passed to the JavaScript runtime for compilation, it triggers a crash in the underlying rquickjs dependency (v0.9.0). The issue was resolved by updating rquickjs to v0.11.0. Administrators can mitigate the risk by using the --deny-scripting flag.
Affected products
- SurrealDB SurrealDB < v2.6.1, < v3.0.0-beta.3
Timeline
- 2026-02-12: advisory: GitHub Security Advisory published
- 2026-07-20: disclosed: NVD publication date