CyberRota Analysis
AI-GeneratedSurrealDB versions prior to 2.0.4 are vulnerable to an uncaught exception handling issue in the parser error rendering code, which can be exploited by authorized clients through malformed queries involving empty string conversions. This vulnerability may lead to server crashes, impacting availability and potentially disrupting services. Organizations using SurrealDB should prioritize updating to the latest version to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. Authorized clients can execute malformed queries with empty string conversions to record, duration, or datetime types that cause a panic in error rendering, crashing the server.
Related CVEs
Other vulnerabilities affecting the same vendor(s)