LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-63760

surrealdb · surrealdb

Published
CVSS7.5
Severityhigh
WeaknessCWE-674
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated attackers can send deeply nested JSON payloads to the WebSocket /rpc endpoint to exhaust server memory and crash the process.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-63760

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-63760.