CVE-2026-63759: SurrealDB before 3.1.0 Denial of Service nested type annotations
Published Jul 20, 2026
·Updated
SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deeply nested type annotations to exhaust server memory and crash the process.
Affected Software
2 affected components
SurrealDB SurrealDB<3.1.0
SurrealDB SurrealDB<3.1.0
Event History
Jul 20, 2026
CVE Published
via MITRE·12:04 PM
Data Sourced
via MITRE·12:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-63759?
The severity of CVE-2026-63759 is medium with a score of 6.5.
2
How do I fix CVE-2026-63759?
To fix CVE-2026-63759, upgrade to SurrealDB version 3.1.0 or later.
3
What type of vulnerability is represented by CVE-2026-63759?
CVE-2026-63759 is a Denial of Service vulnerability due to failure in handling recursion depth limits.
4
Who can exploit CVE-2026-63759?
Authenticated attackers can exploit CVE-2026-63759 by sending queries with deeply nested type annotations.
5
What impact does CVE-2026-63759 have on SurrealDB?
CVE-2026-63759 can lead to server memory exhaustion and process crash.