Junglewise Threat Intelligence

SurrealDB JSON parser denial of service via uncontrolled recursion

Severity: high · CVSS 7.5 · Published 2026-07-20

Technologies: surrealdb (crates.io). Vendors: crates.io, SurrealDB.

Executive brief

SurrealDB is a document database that accepts queries through a WebSocket JSON interface. Due to an incomplete fix, the JSON parser fails to enforce recursion depth limits when processing deeply nested structures. An unauthenticated attacker can send a crafted WebSocket message with nested JSON braces, brackets, or parentheses to exhaust server memory and crash the database process, causing complete service unavailability.

Technical details

The vulnerability is an uncontrolled recursion flaw (CWE-674) in SurrealDB's JSON and value parser components. The expression parser correctly enforces a configured recursion depth limit, but the parse_value and parse_json functions omitted this check—a gap that was overlooked when a related expression parser vulnerability (GHSA-6r8p-hpg7-825g) was previously patched. An unauthenticated attacker with network access to the WebSocket /rpc endpoint can send a single malicious message containing deeply nested JSON structures (e.g., many nested braces, brackets, or parentheses) without authentication or special privileges. This causes the parser to recurse excessively, consuming memory until the server process crashes. The patch enforces recursion depth limits in parse_value and parse_json to match the expression parser behavior; versions 3.1.0 and later are not affected.

Affected products

  • SurrealDB SurrealDB < 3.1.0

Timeline

  • 2026-05-27: disclosed: Original advisory GHSA-q729-696q-g9pq published
  • 2026-05-27: patched: Fix released in version 3.1.0
  • 2026-07-20: advisory: Duplicate advisory GHSA-m464-hj36-96vx published
  • 2026-09-04: other: Duplicate advisory withdrawn

References

Related threats