Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q3vg-g3wv-mfgg

Опубликовано: 20 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression trees, causing stack overflow during query processing and aborting the entire process.

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression trees, causing stack overflow during query processing and aborting the entire process.

EPSS

Процентиль: 27%
0.00346
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 6.5
nvd
22 дня назад

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression trees, causing stack overflow during query processing and aborting the entire process.

EPSS

Процентиль: 27%
0.00346
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-674