SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2025-71393

MEDIUM · CVSS 6.5 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-18 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 2.2.2 with scripting enabled are vulnerable due to improper enforcement of recursion limits in native functions that incorporate embedded JavaScript. This flaw allows authenticated attackers to exploit the system by chaining function calls, potentially leading to infinite recursion and server memory exhaustion. Organizations using SurrealDB with scripting capabilities should prioritize addressing this vulnerability to prevent potential denial-of-service conditions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-71393
Severity
MEDIUM
CVSS
6.5
EPSS
0.26%
Java

Original NVD Description

SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenticated attackers can bypass the recursion limit by chaining native and JavaScript function calls to trigger infinite recursion and exhaust server memory.

Related CVEs

Other vulnerabilities affecting the same vendor(s)