SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-58365

MEDIUM · CVSS 6.5 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-18 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 1.2.0 are vulnerable to an uncaught exception in the query executor, allowing authorized clients to exploit nonexistent built-in functions. This can lead to a server crash, impacting availability and potentially disrupting services. Organizations using affected versions should prioritize patching to mitigate the risk of service interruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2024-58365
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%

Original NVD Description

SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. Authorized clients can craft pre-parsed queries invoking nonexistent functions to trigger a panic that crashes the server.

Related CVEs

Other vulnerabilities affecting the same vendor(s)