Executive brief
SurrealDB is a database management system that executes queries from authorized clients. When the server receives a query calling a nonexistent built-in function, it crashes instead of handling the error gracefully. An authenticated attacker can exploit this to cause a denial of service by deliberately invoking these nonexistent functions, bringing down the database server.
Technical details
The vulnerability is a CWE-248 uncaught exception flaw in SurrealDB's query executor. When a query containing a call to a nonexistent built-in SurrealDB function is executed, the server panics and crashes instead of handling the error. The attack vector is network-based and requires the attacker to be an authorized client with query execution privileges on the server. Attack preconditions include valid authentication and the ability to craft or submit pre-parsed queries (which can occur when using newer client SDKs against older servers). An attacker can trigger a denial of service by crashing the SurrealDB process. The vulnerability affects versions ≤1.1.1 and is patched in version 1.2.0 and later.
Affected products
- SurrealDB SurrealDB <= 1.1.1
Timeline
- 2026-07-18: disclosed
- 2026-02-19: patched: Patch released as version 1.2.0