PatchSiren cyber security CVE debrief
CVE-2026-63737 surrealdb CVE debrief
CVE-2026-63737 is a denial of service vulnerability in SurrealDB versions before 3.1.5. Authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression trees, causing stack overflow during query processing and aborting the entire process. This vulnerability can have a significant impact on the availability of the database and should be addressed promptly.
- Vendor
- surrealdb
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-20
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-20
- Advisory updated
- 2026-07-22
Who should care
Users of SurrealDB versions before 3.1.5 should be aware of this vulnerability and take steps to mitigate it. This includes upgrading to version 3.1.5 or later, and restricting access to the database to trusted users. Additionally, database administrators and security teams should review their current configurations and ensure that they are prepared to respond to potential exploitation attempts.
Technical summary
The vulnerability exists in SurrealDB versions before 3.1.5. An authenticated user can crash the server by submitting a query with a long chain of operators. This can be done by creating a query with tens of thousands of chained operators, which can cause a stack overflow during query processing and abort the entire process. The vulnerability is a denial of service (DoS) vulnerability that can be exploited by authenticated users.
Defensive priority
High
Recommended defensive actions
- Upgrade to SurrealDB version 3.1.5 or later
- Restrict access to the database to trusted users
- Monitor database activity for suspicious queries
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-07-20T12:19:42.857Z and was last modified on 2026-07-21T18:37:56.803Z. The NVD entry is currently Awaiting Analysis. This information is based on the provided source corpus. Further verification by defenders is recommended to ensure accuracy and completeness of the vulnerability details.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T12:19:42.857Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.