CVE-2026-63750

SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer. Attackers can stream WebSocket frames larger than the configured limit across multiple concurrent connections to consume excessive memory and degrade /sql availability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

History

22 Jul 2026, 15:41

Type Values Removed Values Added
CPE cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*
First Time Surrealdb
Surrealdb surrealdb
References () https://github.com/surrealdb/surrealdb/security/advisories/GHSA-65rj-r9fh-jp2v - () https://github.com/surrealdb/surrealdb/security/advisories/GHSA-65rj-r9fh-jp2v - Vendor Advisory, Mitigation
References () https://www.vulncheck.com/advisories/surrealdb-before-memory-amplification-via-sql-websocket - () https://www.vulncheck.com/advisories/surrealdb-before-memory-amplification-via-sql-websocket - Third Party Advisory

20 Jul 2026, 12:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 12:19

Updated : 2026-07-22 15:41


NVD link : CVE-2026-63750

Mitre link : CVE-2026-63750

CVE.ORG link : CVE-2026-63750


JSON object : View

Products Affected

surrealdb

  • surrealdb
CWE
CWE-770

Allocation of Resources Without Limits or Throttling