Skip to content
SurrealDBGHSA-rq86-9m6r-cm3g

SurrealDB has uncaught exception in Net module that leads to database crash

HighCVE-2025-71391 · Published Apr 10, 2025 · updated Jul 19, 2026

A vulnerability was found where an attacker can crash the database via crafting a HTTP query that returns a null byte. The problem relies on an uncaught exception in the `net` module, where the result of the query will be converted to JSON before showing as the HTTP response to the user in the **/sql** endpoint. ### Impact This vulnerability allows any authenticated user to crash a SurrealDB instance by sending a crafted query with a null byte to the /sql endpoint. Where SurrealDB is used as an application backend, it is possible that an application user can crash the SurrealDB instance and thus the supported application through crafted inputs that exploit this attack vector. ### Patches A patch has been introduced that ensures the error is caught and converted as an error. - Versions 2.2.2, 2.1.5 and 2.0.5 and later are not affected by this isssue ### Workarounds Affected users who are unable to update may want to limit the ability of untrusted clients to run arbitrary queries in the affected versions of SurrealDB. To limit the impact of the denial of service, SurrealDB administrators may also want to ensure that the SurrealDB process is running so that it can be automaticall...

GitHub advisory

Affected versions

PackageAffectedFixed in
surrealdb
crates.io
>= 2.2.0, < 2.2.22.2.2
>= 2.1.0, < 2.1.52.1.5
< 2.0.52.0.5
Details and references

A vulnerability was found where an attacker can crash the database via crafting a HTTP query that returns a null byte. The problem relies on an uncaught exception in the `net` module, where the result of the query will be converted to JSON before showing as the HTTP response to the user in the **/sql** endpoint. ### Impact This vulnerability allows any authenticated user to crash a SurrealDB instance by sending a crafted query with a null byte to the /sql endpoint. Where SurrealDB is used as an application backend, it is possible that an application user can crash the SurrealDB instance and thus the supported application through crafted inputs that exploit this attack vector. ### Patches A patch has been introduced that ensures the error is caught and converted as an error. - Versions 2.2.2, 2.1.5 and 2.0.5 and later are not affected by this isssue ### Workarounds Affected users who are unable to update may want to limit the ability of untrusted clients to run arbitrary queries in the affected versions of SurrealDB. To limit the impact of the denial of service, SurrealDB administrators may also want to ensure that the SurrealDB process is running so that it can be automatically re-started after a crash. Where SurrealDB is used as an application backend, ensure sanitisation of input at the application layer to prevent injection attacks. ### References https://github.com/surrealdb/surrealdb/pull/5647

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-248
Also known as
CVE-2025-71391

More SurrealDB advisories

All SurrealDB
Advisory
SurrealDB CPU exhaustion via custom functions result in total DoS
HighApr 11, 2025
SurrealDB no JavaScript script function default timeout could facilitate DoS
LowApr 11, 2025
SurrealDB memory exhaustion via string::replace using regex
HighApr 11, 2025
SurrealDB server-takeover via SurrealQL injection on backup import
CriticalApr 11, 2025
SurrealDB has local file read of 2-column TSV files via analyzers
LowApr 10, 2025
SurrealDB vulnerable to memory exhaustion via nested functions and scripts
MediumApr 10, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.