Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-63737

Опубликовано: 20 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression trees, causing stack overflow during query processing and aborting the entire process.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.1.5 (исключая)

EPSS

Процентиль: 27%
0.00346
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 6.5
github
22 дня назад

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression trees, causing stack overflow during query processing and aborting the entire process.

EPSS

Процентиль: 27%
0.00346
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-674