CVE-2025-71393: SurrealDB before 2.2.2 Memory Exhaustion via Nested Functions
SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenticated attackers can bypass the recursion limit by chaining native and JavaScript function calls to trigger infinite recursion and exhaust server memory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 2.2.2 - Compensating control
If you cannot immediately upgrade SurrealDB, disable or restrict scripting so embedded JavaScript that issues new queries cannot chain native and JavaScript function calls to bypass recursion limits.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71393?
The severity of CVE-2025-71393 is medium, rated at 6 on the CVSS scale.
How do I fix CVE-2025-71393?
To mitigate CVE-2025-71393, upgrade SurrealDB to version 2.2.2 or later where the recursion limits are properly enforced.
What causes CVE-2025-71393 vulnerability?
CVE-2025-71393 occurs due to improper enforcement of recursion limits in SurrealDB when scripting is enabled, allowing attackers to create infinite recursion.
Who is affected by CVE-2025-71393?
All authenticated users of SurrealDB versions prior to 2.2.2 with scripting enabled are potentially affected by CVE-2025-71393.
What are the potential impacts of CVE-2025-71393?
CVE-2025-71393 can lead to memory exhaustion, resulting in Denial of Service for the affected SurrealDB server.