Executive brief
SurrealDB is a document database that accepts queries through a WebSocket JSON interface. Due to an incomplete fix, the JSON parser fails to enforce recursion depth limits when processing deeply nested structures. An unauthenticated attacker can send a crafted WebSocket message with nested JSON braces, brackets, or parentheses to exhaust server memory and crash the database process, causing complete service unavailability.
Technical details
The vulnerability is an uncontrolled recursion flaw (CWE-674) in SurrealDB's JSON and value parser components. The expression parser correctly enforces a configured recursion depth limit, but the parse_value and parse_json functions omitted this check—a gap that was overlooked when a related expression parser vulnerability (GHSA-6r8p-hpg7-825g) was previously patched. An unauthenticated attacker with network access to the WebSocket /rpc endpoint can send a single malicious message containing deeply nested JSON structures (e.g., many nested braces, brackets, or parentheses) without authentication or special privileges. This causes the parser to recurse excessively, consuming memory until the server process crashes. The patch enforces recursion depth limits in parse_value and parse_json to match the expression parser behavior; versions 3.1.0 and later are not affected.
Affected products
- SurrealDB SurrealDB < 3.1.0
Timeline
- 2026-05-27: disclosed: Original advisory GHSA-q729-696q-g9pq published
- 2026-05-27: patched: Fix released in version 3.1.0
- 2026-07-20: advisory: Duplicate advisory GHSA-m464-hj36-96vx published
- 2026-09-04: other: Duplicate advisory withdrawn