Skip to content
SurrealDBGHSA-m7rc-8w7m-r9qr

SurrealDB vulnerable to memory exhaustion via nested functions and scripts

MediumCVE-2025-71393 · Published Apr 10, 2025 · updated Jul 19, 2026

In order to prevent DoS situations due to infinite recursions, SurrealDB implements a limit of nested calls for both native functions and embedded JavaScript functions. However, in SurrealDB instances with embedded scripting functions enabled, it was found that this limit can be circumvented by utilizing both at the same time. If a native function contains JavaScript which issues a new query that calls that function, the recursion limit is not triggered. Once executed, SurrealDB will follow the path of infinite recursions until the system runs out of memory, prior to the recursion limit being triggered. This vulnerability can only affect SurrealDB servers explicitly enabling the scripting capability with `--allow-scripting` or `--allow-all` and equivalent environment variables `SURREAL_CAPS_ALLOW_SCRIPT=true` and `SURREAL_CAPS_ALLOW_ALL=true`. This issue was discovered and patched during an code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v4 assessment. ### Impact For SurrealDB instances with embedded scripting functions enabled, this attack could be used to perform a DoS attack on t...

GitHub advisory

Affected versions

PackageAffectedFixed in
surrealdb
crates.io
>= 2.2.0, < 2.2.22.2.2
>= 2.1.0, < 2.1.52.1.5
< 2.0.52.0.5
Details and references

In order to prevent DoS situations due to infinite recursions, SurrealDB implements a limit of nested calls for both native functions and embedded JavaScript functions. However, in SurrealDB instances with embedded scripting functions enabled, it was found that this limit can be circumvented by utilizing both at the same time. If a native function contains JavaScript which issues a new query that calls that function, the recursion limit is not triggered. Once executed, SurrealDB will follow the path of infinite recursions until the system runs out of memory, prior to the recursion limit being triggered. This vulnerability can only affect SurrealDB servers explicitly enabling the scripting capability with `--allow-scripting` or `--allow-all` and equivalent environment variables `SURREAL_CAPS_ALLOW_SCRIPT=true` and `SURREAL_CAPS_ALLOW_ALL=true`. This issue was discovered and patched during an code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v4 assessment. ### Impact For SurrealDB instances with embedded scripting functions enabled, this attack could be used to perform a DoS attack on the server by an authenticated user. ### Patches A patch has been created that further limits scripting function call limit recursion depth and disallows multiple calls to `surreadb.query()` to run in parallel in a scripting function. - Versions 2.0.5, 2.1.5, 2.2.2 and later are not affected by this issue. ### Workarounds Deny execution of embedded scripting functions through the configuration of [capabilities](https://surrealdb.com/docs/surrealdb/security/capabilities#capabilities) by starting SurrealDB with the `--deny-scripting` flag or the equivalent environment variable `SURREAL_CAPS_DENY_SCRIPT=true`. This has a usability implication, although scripting functions are disabled by default. ### References [SurrealDB Documentation - Capabilities](https://surrealdb.com/docs/surrealdb/security/capabilities) [SurrealQL Documentation - Scripting Functions](https://surrealdb.com/docs/surrealql/functions/script)

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-674
Also known as
CVE-2025-71393

More SurrealDB advisories

All SurrealDB
Advisory
SurrealDB CPU exhaustion via custom functions result in total DoS
HighApr 11, 2025
SurrealDB no JavaScript script function default timeout could facilitate DoS
LowApr 11, 2025
SurrealDB memory exhaustion via string::replace using regex
HighApr 11, 2025
SurrealDB server-takeover via SurrealQL injection on backup import
CriticalApr 11, 2025
SurrealDB has local file read of 2-column TSV files via analyzers
LowApr 10, 2025
SurrealDB has uncaught exception in Net module that leads to database crash
HighApr 10, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.