cvedb.io
CVE-2026-63737
MEDIUM · CVSS 6.5
EPSS exploitation probability: 0%
Published 2026-07-20T12:19:42.857 · Last modified 2026-07-20T15:16:45.503

Summary

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression trees, causing stack overflow during query processing and aborting the entire process.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.