CVE-2025-71395: Surrealdb

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to restrict resulting string length when using regex patterns. An authenticated attacker can craft a malicious query to exhaust server memory through unbounded string allocations, causing denial of service.

Affected products

  • Surrealdb Surrealdb: before 2.0.5 (fixed in 2.0.5); from 2.1.0, before 2.1.5 (fixed in 2.1.5); from 2.2.0, before 2.2.2 (fixed in 2.2.2)

Published 2026-07-18. Last modified 2026-09-29.