SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63747

HIGH · CVSS 7.5 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 3.1.0 are vulnerable to a denial of service attack due to a flaw in the RPC use handler, which can be triggered when the database is configured without a namespace. Unauthenticated attackers can exploit this vulnerability by sending a malformed WebSocket message to the /rpc endpoint, leading to server crashes. Organizations using affected versions of SurrealDB should prioritize updating to mitigate the risk of service disruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63747
Severity
HIGH
CVSS
7.5
EPSS
0.36%

Original NVD Description

SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send a malformed WebSocket message to the /rpc endpoint to crash the server process.

Related CVEs

Other vulnerabilities affecting the same vendor(s)