GHSA-56pq-53x9-mxc4HighCVSS 6.5

SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when...

Published
July 20, 2026
Last Modified
July 20, 2026

🔗 CVE IDs covered (1)

📋 Description

SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deeply nested type annotations to exhaust server memory and crash the process.

🔗 References (4)