CVE-2026-63750

SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer. Attackers can stream WebSocket frames larger than the configured limit across multiple concurrent connections to consume excessive memory and degrade /sql availability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-20 12:19

Updated : 2026-07-22 15:41


NVD link : CVE-2026-63750

Mitre link : CVE-2026-63750

CVE.ORG link : CVE-2026-63750


JSON object : View

Products Affected

surrealdb

  • surrealdb
CWE
CWE-770

Allocation of Resources Without Limits or Throttling