SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2025-71391

MEDIUM · CVSS 6.5 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-18 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 2.2.2 are vulnerable to an uncaught exception in the net module, which can be exploited by authenticated users to crash the database by sending specially crafted HTTP queries with null bytes to the /sql endpoint. This vulnerability can disrupt database operations and affect any applications relying on SurrealDB. Organizations using affected versions should prioritize updating to version 2.2.2 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-71391
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%

Original NVD Description

SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send crafted HTTP queries containing null bytes to the /sql endpoint, causing an unhandled exception that crashes the SurrealDB instance and any dependent applications.

Related CVEs

Other vulnerabilities affecting the same vendor(s)