PatchSiren cyber security CVE debrief
CVE-2026-63759 surrealdb CVE debrief
CVE-2026-63759 is a high-severity vulnerability in SurrealDB before version 3.1.0. The issue arises from the failure to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can exploit this by sending queries with deeply nested type annotations, leading to server memory exhaustion and process crashes.
- Vendor
- surrealdb
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-20
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-20
- Advisory updated
- 2026-07-22
Who should care
Organizations using SurrealDB versions prior to 3.1.0 should prioritize updating to the latest version to mitigate this vulnerability. Additionally, security teams and administrators responsible for databases and query processing systems should be aware of the potential for denial-of-service attacks through deeply nested type annotations.
Technical summary
The vulnerability in SurrealDB before 3.1.0 stems from inadequate recursion depth limits in the type/kind parser. This allows attackers to craft queries with deeply nested type annotations, which can cause the server to exhaust its memory and crash. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Successful exploitation requires authentication and can be achieved through specially crafted queries.
Defensive priority
High priority should be given to updating SurrealDB to version 3.1.0 or later. In the meantime, organizations can implement compensating controls such as monitoring for unusual query patterns, limiting query complexity, and enhancing authentication and authorization measures.
Recommended defensive actions
- Update SurrealDB to version 3.1.0 or later
- Monitor for unusual query patterns indicative of potential exploitation attempts
- Implement additional authentication and authorization measures for database access
- Limit query complexity and depth to prevent exploitation
- Enhance logging and monitoring to detect and respond to potential attacks
Evidence notes
The CVE record was published on 2026-07-20T12:19:46.047Z and was last modified on 2026-07-21T18:37:56.803Z. The NVD entry is currently awaiting analysis. References include the official CVE record, NVD details, and advisories from Vulncheck.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-63759 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-63759
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-63759 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-63759
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/surrealdb/surrealdb/security/advisories/GHSA-q8qp-67f9-wr3f
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-nested-type-annotations
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.