CVE-2024-58370EPSS p39.9%
CVE-2024-58370CVE-2024-58370
surrealdb / surrealdb
Description
SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms. Authorized attackers can submit queries with excessive nesting depth to cause stack overflow and crash the server.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.49% probability of exploitation · percentile 39.9% · 2026-10-06T12:00:23Z |
| Last modified | 2026-08-19 |