CVE-2024-58370
- EPSS 0.28%
- Veröffentlicht 18.07.2026 13:10:09
- Zuletzt bearbeitet 19.08.2026 17:50:29
SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms. Authorized attackers can submit queries with excessive nesting depth to cause stack ove...
CVE-2024-58369
- EPSS 0.25%
- Veröffentlicht 18.07.2026 13:10:08
- Zuletzt bearbeitet 13.08.2026 15:22:49
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB serve...
CVE-2024-58368
- EPSS 0.39%
- Veröffentlicht 18.07.2026 13:10:08
- Zuletzt bearbeitet 13.08.2026 15:25:43
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenticated attackers can send crafted HTTP requests with malformed header values to trigger an uncaught ex...
CVE-2024-58367
- EPSS 0.21%
- Veröffentlicht 18.07.2026 13:10:07
- Zuletzt bearbeitet 13.08.2026 15:35:38
SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to access unauthorized field values through various query techniques. Attackers can exploit SELECT VALU...
CVE-2024-58366
- EPSS 0.32%
- Veröffentlicht 18.07.2026 13:10:06
- Zuletzt bearbeitet 13.08.2026 16:03:58
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or...
CVE-2024-58365
- EPSS 0.25%
- Veröffentlicht 18.07.2026 13:10:06
- Zuletzt bearbeitet 12.08.2026 18:10:28
SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. Authorized clients can craft pre-parsed queries invoking nonexistent functions to trigger a pan...
CVE-2024-58364
- EPSS 0.25%
- Veröffentlicht 18.07.2026 13:10:05
- Zuletzt bearbeitet 12.08.2026 18:12:45
SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. Authorized clients can submit malformed queries that trigger a panic in the span re...
CVE-2024-58363
- EPSS 0.19%
- Veröffentlicht 18.07.2026 13:10:04
- Zuletzt bearbeitet 12.08.2026 18:37:21
SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers with an authenticated session can impersonate an unrelated user in a different database if a user reco...
CVE-2024-58362
- EPSS 0.38%
- Veröffentlicht 18.07.2026 13:10:04
- Zuletzt bearbeitet 12.08.2026 18:40:17
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. When a record access method defines a SIGNIN or SIGN...
CVE-2024-58361
- EPSS 0.25%
- Veröffentlicht 18.07.2026 13:10:03
- Zuletzt bearbeitet 12.08.2026 18:46:06
SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. Authorized clients can execute malformed queries with empty string conversions to record, duration,...