CVE-2026-63760: SurrealDB before 3.1.0 Denial of Service via JSON Parser
SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated attackers can send deeply nested JSON payloads to the WebSocket /rpc endpoint to exhaust server memory and crash the process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63760?
The severity of CVE-2026-63760 is high with a score of 7.5.
How do I fix CVE-2026-63760?
To fix CVE-2026-63760, upgrade SurrealDB to version 3.1.0 or later.
What type of attack does CVE-2026-63760 enable?
CVE-2026-63760 enables a denial of service attack through the exploitation of the JSON parser.
Which software is affected by CVE-2026-63760?
CVE-2026-63760 affects SurrealDB versions prior to 3.1.0.
How can an attacker exploit CVE-2026-63760?
An attacker can exploit CVE-2026-63760 by sending deeply nested JSON payloads to the WebSocket /rpc endpoint.