Vulnerability Description
SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenticated attackers can bypass the recursion limit by chaining native and JavaScript function calls to trigger infinite recursion and exhaust server memory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Surrealdb | Surrealdb | < 2.0.5 |
Related Weaknesses (CWE)
References
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-m7rc-8w7m-r9qrVendor Advisory
- https://www.vulncheck.com/advisories/surrealdb-before-memory-exhaustion-via-nestThird Party Advisory
FAQ
What is CVE-2025-71393?
CVE-2025-71393 is a vulnerability with a CVSS score of 6.5 (MEDIUM). SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenticated attackers can bypass t...
How severe is CVE-2025-71393?
CVE-2025-71393 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-71393?
Check the references section above for vendor advisories and patch information. Affected products include: Surrealdb Surrealdb.