CVE-2026-63750: SurrealDB before 3.1.0 Memory Amplification via /sql WebSocket
SurrealDB versions before 3.1.0 fail to apply the SURREALWEBSOCKETMAXMESSAGESIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer. Attackers can stream WebSocket frames larger than the configured limit across multiple concurrent connections to consume excessive memory and degrade /sql availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0 - Configuration
Ensure SurrealDB correctly enforces the configured SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit for anonymous /sql WebSocket connections to prevent buffering unbounded frames in the per-connection read buffer.
SurrealDB /sql WebSocket SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE = (apply configured limit)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63750?
The severity of CVE-2026-63750 is rated medium with a score of 6.9.
How do I fix CVE-2026-63750?
To fix CVE-2026-63750, upgrade SurrealDB to version 3.1.0 or later.
What type of vulnerability is CVE-2026-63750?
CVE-2026-63750 is a memory amplification vulnerability affecting WebSocket connections.
What is the impact of CVE-2026-63750?
The impact of CVE-2026-63750 allows attackers to buffer unbounded frames in the read buffer, potentially leading to denial of service.
Which software is affected by CVE-2026-63750?
CVE-2026-63750 affects all versions of SurrealDB before 3.1.0.