Skip to content
surrealdbGHSA-q8qp-67f9-wr3f

SurrealDB vulnerable to Denial of Service due to nested types annotations

Medium6.5Published Jul 1, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
surrealdb
crates.io
< 3.1.03.1.0
Details and references

The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., `array<option<array<option<...>>>>`) and exhaust server memory, crashing the process. This is an incomplete fix for [GHSA-6r8p-hpg7-825g](https://github.com/surrealdb/surrealdb/security/advisories/GHSA-6r8p-hpg7-825g), which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ### Impact An authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. ### Patches A patch has been introduced that wraps `parse_concrete_kind` and the `OPTION<...>` arm of `parse_inner_kind` with `enter_object_recursion!`, bounding the recursive cycle `parse_concrete_kind → parse_inner_kind → parse_inner_single_kind → parse_concrete_kind` at the configured `object_recursion_limit` (default 100). Regression tests cover both cast and `DEFINE FIELD` paths. - Versions 3.1.0 and later are not affected by this issue. ### Workarounds Restrict the ability of untrusted users to execute arbitrary queries via the `--deny-arbitrary-query` capability flag for the affected user classes (guest, record, or system). Disabling untrusted access to the WebSocket `/rpc` endpoint also prevents exploitation; the HTTP `/sql` endpoint's 1 MiB body limit constrains nesting to a depth where OOM is not feasible.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-674

More surrealdb advisories

All
DateAdvisory
Jul 1SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
GHSA-5qfp-32cf-69jhHigh8.8fixed in 3.1.0
Jul 1SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
GHSA-4vgr-h27g-cf9pHigh8.1fixed in 3.1.0
Jul 1SurrealDB has Denial of Service in JSON parser due to nested objects
CVE-2026-63760High7.5fixed in 3.1.0
Jul 1SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
GHSA-wjjj-24cx-f28gHigh7.5fixed in 3.1.0
Jul 1SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
CVE-2026-63755Medium6.5fixed in 3.1.0
Jul 1SurrealDB: Graph traversal bypasses table SELECT permissions
CVE-2026-63746Medium6.5fixed in 3.1.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.