SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-58359

MEDIUM · CVSS 6.5 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-18 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 2.1.0 are susceptible to a denial of service vulnerability due to a flaw in the sorting mechanism when the ORDER BY rand() clause is used. This allows authorized clients to execute specific queries that can cause the server to crash. Organizations utilizing affected versions should prioritize patching to mitigate potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2024-58359
Severity
MEDIUM
CVSS
6.5
EPSS
0.31%

Original NVD Description

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clients can execute queries with ORDER BY rand() to trigger a panic in the sorting function, crashing the server.

Related CVEs

Other vulnerabilities affecting the same vendor(s)