Vulnerability Description
SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated attackers can send deeply nested JSON payloads to the WebSocket /rpc endpoint to exhaust server memory and crash the process.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Surrealdb | Surrealdb | < 3.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-q729-696q-g9pqVendor AdvisoryMitigation
- https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-jsonThird Party Advisory
FAQ
What is CVE-2026-63760?
CVE-2026-63760 is a vulnerability with a CVSS score of 7.5 (HIGH). SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated attackers can send de...
How severe is CVE-2026-63760?
CVE-2026-63760 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-63760?
Check the references section above for vendor advisories and patch information. Affected products include: Surrealdb Surrealdb.