CVE-2024-58361

SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. Authorized clients can execute malformed queries with empty string conversions to record, duration, or datetime types that cause a panic in error rendering, crashing the server.
Configurations

No configuration.

History

18 Jul 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-18 14:17

Updated : 2026-07-21 18:37


NVD link : CVE-2024-58361

Mitre link : CVE-2024-58361

CVE.ORG link : CVE-2024-58361


JSON object : View

Products Affected

No product.

CWE
CWE-248

Uncaught Exception