SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-58358

MEDIUM · CVSS 4.9 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-18 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 2.1.0 are vulnerable to a denial of service attack due to improper handling of role conversions, allowing privileged users to create accounts with nonexistent roles. An attacker can exploit this flaw by logging in with an invalid role, leading to an uncaught panic that crashes the server. Organizations using affected versions should prioritize updating to mitigate potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2024-58358
Severity
MEDIUM
CVSS
4.9
EPSS
0.33%

Original NVD Description

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server.

Related CVEs

Other vulnerabilities affecting the same vendor(s)