CVE-2026-63762: SurrealDB before v2.6.1 Denial of Service via scripting

Published Jul 20, 2026
·
Updated

SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript scripting engine, which is enabled via the --allow-scripting capability (disabled by default). Any user able to execute arbitrary queries — including unauthenticated guests when --allow-guests is enabled — can use built-in string functions to construct a large string and pass it to the JavaScript runtime for compilation, triggering a null pointer dereference in the underlying QuickJS-NG engine. This causes the server process to terminate immediately without graceful shutdown, requiring a manual restart. The issue was fixed by updating the rquickjs dependency from v0.9.0 to v0.11.0.

Affected Software

21 affected components
SurrealDB SurrealDB<2.6.1, <3.0.0-beta.3
SurrealDB SurrealDB<2.6.1
SurrealDB SurrealDB=3.0.0-alpha1
SurrealDB SurrealDB=3.0.0-alpha10
SurrealDB SurrealDB=3.0.0-alpha11
SurrealDB SurrealDB=3.0.0-alpha12
SurrealDB SurrealDB=3.0.0-alpha13
SurrealDB SurrealDB=3.0.0-alpha14
SurrealDB SurrealDB=3.0.0-alpha16
SurrealDB SurrealDB=3.0.0-alpha17
SurrealDB SurrealDB=3.0.0-alpha18
SurrealDB SurrealDB=3.0.0-alpha2
SurrealDB SurrealDB=3.0.0-alpha3
SurrealDB SurrealDB=3.0.0-alpha4
SurrealDB SurrealDB=3.0.0-alpha5
SurrealDB SurrealDB=3.0.0-alpha6
SurrealDB SurrealDB=3.0.0-alpha7
SurrealDB SurrealDB=3.0.0-alpha8
SurrealDB SurrealDB=3.0.0-alpha9
SurrealDB SurrealDB=3.0.0-beta1
SurrealDB SurrealDB=3.0.0-beta2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rquickjs dependency to a version that resolves this vulnerability.

    Fixed in v0.11.0
  2. Configuration

    Ensure --allow-scripting is disabled unless required, since the embedded JavaScript scripting engine is enabled via this capability (disabled by default).

    SurrealDB --allow-scripting capability = disabled (do not enable)
  3. Operational

    After updating rquickjs (v0.9.0 -> v0.11.0) and/or applying the SurrealDB upgrade, manually restart the server because the vulnerable process may terminate immediately without a graceful shutdown.

Event History

Jul 20, 2026
CVE Published
via MITRE·12:04 PM
Data Sourced
via MITRE·12:04 PM
DescriptionWeakness
Data Sourced
via NVD·12:19 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-63762?

The severity of CVE-2026-63762 is medium with a CVSS score of 6.

2

What vulnerability does CVE-2026-63762 describe?

CVE-2026-63762 describes a denial of service vulnerability in SurrealDB's embedded JavaScript scripting engine.

3

How do I fix CVE-2026-63762?

To fix CVE-2026-63762, upgrade SurrealDB to version 2.6.1 or later.

4

Who is affected by CVE-2026-63762?

Any user able to execute arbitrary queries on SurrealDB, including unauthenticated guests, is affected by CVE-2026-63762.

5

What version of SurrealDB is vulnerable to CVE-2026-63762?

SurrealDB versions before 2.6.1 and before 3.0.0-beta.3 are vulnerable to CVE-2026-63762.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203