CVE-2024-58361

SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. Authorized clients can execute malformed queries with empty string conversions to record, duration, or datetime types that cause a panic in error rendering, crashing the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-18 14:17

Updated : 2026-08-12 18:46


NVD link : CVE-2024-58361

Mitre link : CVE-2024-58361

CVE.ORG link : CVE-2024-58361


JSON object : View

Products Affected

surrealdb

  • surrealdb
CWE
CWE-248

Uncaught Exception