GHSA-3h9v-xwgf-h5c5HighCVSS 6.5

SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time()...

Published
July 18, 2026
Last Modified
July 18, 2026

🔗 CVE IDs covered (1)

📋 Description

SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_opt. Authorized clients can repeatedly invoke rand::time() to reliably trigger server panics and cause denial of service.

🔗 References (4)