SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-58369

MEDIUM · CVSS 6.5 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-18 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 1.1.1 are vulnerable to improper validation of custom parameters and functions, allowing authorized clients to invoke these entities at unauthorized levels. This can lead to a server panic and result in a denial of service. Organizations using affected versions should prioritize updating to mitigate potential disruptions in service.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2024-58369
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%

Original NVD Description

SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)