Executive brief
SurrealDB is a multi-model database used for managing complex data structures. A vulnerability allows an authenticated user to crash the database server by sending a specially crafted query with a long chain of mathematical or logical operators. This results in a complete service outage for all users on the affected instance until the database is manually or automatically restarted.
Technical details
A stack overflow vulnerability exists in SurrealDB due to uncontrolled recursion (CWE-674) when processing deep expression trees. While SurrealDB has query and object recursion limits, the Pratt parser iteratively appends operators to a flat chain, creating an unbounded expression tree. When this tree is later walked recursively during dropping, formatting, or execution, it exhausts the thread stack and aborts the process. The vulnerability is reachable via the /sql or /rpc endpoints by any authenticated user with query privileges. A fix was introduced in version 3.1.5 which implements a dedicated 'expr_recursion_limit' to bound the depth of operator trees during parsing.
Affected products
- SurrealDB SurrealDB >= 3.0.0, < 3.1.5
Timeline
- 2026-06-19: disclosed
- 2026-06-19: advisory
- 2026-06-19: patched: Fixed in version 3.1.5