Junglewise Threat Intelligence

SurrealDB query executor uncaught exception denial of service

Severity: medium · CVSS 6.5 · Published 2026-07-18

Technologies: surrealdb (crates.io). Vendors: SurrealDB, crates.io.

Executive brief

SurrealDB is a database management system that executes queries from authorized clients. When the server receives a query calling a nonexistent built-in function, it crashes instead of handling the error gracefully. An authenticated attacker can exploit this to cause a denial of service by deliberately invoking these nonexistent functions, bringing down the database server.

Technical details

The vulnerability is a CWE-248 uncaught exception flaw in SurrealDB's query executor. When a query containing a call to a nonexistent built-in SurrealDB function is executed, the server panics and crashes instead of handling the error. The attack vector is network-based and requires the attacker to be an authorized client with query execution privileges on the server. Attack preconditions include valid authentication and the ability to craft or submit pre-parsed queries (which can occur when using newer client SDKs against older servers). An attacker can trigger a denial of service by crashing the SurrealDB process. The vulnerability affects versions ≤1.1.1 and is patched in version 1.2.0 and later.

Affected products

  • SurrealDB SurrealDB <= 1.1.1

Timeline

  • 2026-07-18: disclosed
  • 2026-02-19: patched: Patch released as version 1.2.0

References

Related threats