Loading...
Skip to main content

CVE-2025-71393

MEDIUM

SurrealDB vulnerable to memory exhaustion via nested functions and scripts

Published April 10, 2025Updated July 19, 2026Source: osv

Summary

In order to prevent DoS situations due to infinite recursions, SurrealDB implements a limit of nested calls for both native functions and embedded JavaScript functions. However, in SurrealDB instances with embedded scripting functions enabled, it was found that this limit can be circumvented by utilizing both at the same time. If a native function contains JavaScript which issues a new query that calls that function, the recursion limit is not triggered. Once executed, SurrealDB will follow the path of infinite recursions until the system runs out of memory, prior to the recursion limit being triggered. This vulnerability can only affect SurrealDB servers explicitly enabling the scripting capability with `--allow-scripting` or `--allow-all` and equivalent environment variables `SURREAL_CAPS_ALLOW_SCRIPT=true` and `SURREAL_CAPS_ALLOW_ALL=true`. This issue was discovered and patched during an code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v4 assessment. ### Impact For SurrealDB instances with embedded scripting functions enabled, this attack could be used to perform a DoS attack on the server by an authenticated user. ### Patches A patch has been created that further limits scripting function call limit recursion depth and disallows multiple calls to `surreadb.query()` to run in parallel in a scripting function. - Versions 2.0.5, 2.1.5, 2.2.2 and later are not affected by this issue. ### Workarounds Deny execution of embedded scripting functions through the configuration of [capabilities](https://surrealdb.com/docs/surrealdb/security/capabilities#capabilities) by starting SurrealDB with the `--deny-scripting` flag or the equivalent environment variable `SURREAL_CAPS_DENY_SCRIPT=true`. This has a usability implication, although scripting functions are disabled by default. ### References [SurrealDB Documentation - Capabilities](https://surrealdb.com/docs/surrealdb/security/capabilities) [SurrealQL Documentation - Scripting Functions](https://surrealdb.com/docs/surrealql/functions/script)

Remediation

Upgrade to the fixed version using your package manager.

Cargo
Update surrealdb to 2.1.5 or later
cargo update -p surrealdb --precise 2.1.5
Cargo
Update surrealdb to 2.2.2 or later
cargo update -p surrealdb --precise 2.2.2
Cargo
Update surrealdb to 2.0.5 or later
cargo update -p surrealdb --precise 2.0.5

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (3)

PackageEcosystemAffectedFixed In
surrealdb
crates.io
All versions2.1.5
surrealdb
crates.io
All versions2.2.2
surrealdb
crates.io
All versions2.0.5

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 6.1 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Confidentiality
Integrity
Availability

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Frequently Asked Questions

What is CVE-2025-71393?
SurrealDB vulnerable to memory exhaustion via nested functions and scripts This vulnerability has been assigned a severity rating of MEDIUM (CVSS score: 6.1/10).
How do I check if my project is affected by CVE-2025-71393?
CVE-2025-71393 affects surrealdb. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2025-71393 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
6.1

Exploitation requires specific conditions or has limited impact. Remediate within weeks.

Also Known As

GHSA-m7rc-8w7m-r9qr

Related CVEs

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies