Junglewise Threat Intelligence

SurrealDB memory amplification in /sql WebSocket endpoint

Severity: medium · CVSS 5.3 · Published 2026-07-01

Technologies: surrealdb (crates.io). Vendors: SurrealDB, crates.io.

Executive brief

SurrealDB, a multi-model database, is vulnerable to a denial-of-service attack through its SQL WebSocket interface. An unauthenticated attacker can send extremely large data packets that bypass configured memory limits, potentially causing the database to crash or become unresponsive due to memory exhaustion. This could disrupt business operations and data availability for legitimate users.

Technical details

A resource exhaustion vulnerability (CWE-770) exists in SurrealDB's `/sql` WebSocket upgrade handler. The handler failed to propagate the `SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE` configuration to the underlying WebSocket protocol layer for anonymous connections. This allowed unauthenticated attackers to stream large WebSocket frames (up to 16 MiB per frame / 64 MiB per message) into per-connection read buffers before authentication checks occurred. Exploitation can lead to Out-Of-Memory (OOM) conditions and service degradation. Additionally, the endpoint bypassed certain capability checks like `--deny-http sql`, though this did not grant unauthorized data access. The issue is fixed in version 3.1.0 by enforcing capability checks and message size limits before the WebSocket upgrade.

Affected products

  • surrealdb surrealdb < 3.1.0

Timeline

  • 2026-05-10: patched: Fix committed to repository
  • 2026-05-27: disclosed: Initial advisory publication
  • 2026-07-01: advisory: Advisory updated and reviewed

References

Related threats