SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send crafted HTTP queries containing null bytes to the /sql endpoint, causing an unhandled exception that crashes the SurrealDB instance and any dependent applications.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Surrealdb
Surrealdb surrealdb |
|
| Vendors & Products |
Surrealdb
Surrealdb surrealdb |
Mon, 20 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 18 Jul 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send crafted HTTP queries containing null bytes to the /sql endpoint, causing an unhandled exception that crashes the SurrealDB instance and any dependent applications. | |
| Title | SurrealDB before 2.2.2 Denial of Service via /sql endpoint | |
| Weaknesses | CWE-248 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-07-18T13:10:10.977Z
Updated: 2026-07-20T15:13:19.190Z
Reserved: 2026-07-16T12:14:41.770Z
Link: CVE-2025-71391
Updated: 2026-07-20T15:13:14.608Z
No data.
No data.