CVE-2026-63750: Surrealdb
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer. Attackers can stream WebSocket frames larger than the configured limit across multiple concurrent connections to consume excessive memory and degrade /sql availability.
Affected products
- Surrealdb Surrealdb: before 3.1.0 (fixed in 3.1.0)
Published 2026-07-20. Last modified 2026-07-22.