SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms. Authorized attackers can submit queries with excessive nesting depth to cause stack overflow and crash the server.
References
Configurations
No configuration.
History
18 Jul 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-18 14:17
Updated : 2026-07-18 14:17
NVD link : CVE-2024-58370
Mitre link : CVE-2024-58370
CVE.ORG link : CVE-2024-58370
JSON object : View
Products Affected
No product.
CWE
CWE-674
Uncontrolled Recursion
