CVE-2026-63747: SurrealDB before 3.1.0 Denial of Service via malformed RPC use
SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send a malformed WebSocket message to the /rpc endpoint to crash the server process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0 - Compensating control
Mitigate exposure by restricting network access to the SurrealDB /rpc WebSocket endpoint so unauthenticated attackers cannot reach it until patched.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63747?
The severity of CVE-2026-63747 is rated high with a score of 8.7.
How does CVE-2026-63747 affect SurrealDB?
CVE-2026-63747 allows unauthenticated attackers to cause a denial of service by sending malformed WebSocket messages to the /rpc endpoint.
How do I fix CVE-2026-63747?
To fix CVE-2026-63747, upgrade SurrealDB to version 3.1.0 or later.
What is the impact of CVE-2026-63747?
The impact of CVE-2026-63747 is that it can crash the server process, resulting in a denial of service.
Can an attacker exploit CVE-2026-63747 without authentication?
Yes, an attacker can exploit CVE-2026-63747 without authentication.