PT-2024-40357 · Surrealdb · Surrealdb

Published

2024-01-18

·

Updated

2024-01-18

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 1.1.0
Description The issue affects the SurrealDB HTTP REST API, where the ID, DB, and NS headers fail to parse when containing special characters, causing a panic that crashes the SurrealDB server, leading to denial of service. An unauthenticated client can exploit this by issuing an HTTP request with affected headers containing special characters. This issue only affects the SurrealDB binary, not the SurrealDB library.
Recommendations For versions prior to 1.1.0, update to version 1.1.0 or later to resolve the issue. As a temporary workaround, consider limiting untrusted access to the SurrealDB HTTP REST API unless required by the application. Additionally, ensure the SurrealDB process is configured to automatically restart after a crash to minimize the impact of the denial of service.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-M24X-R6Q3-2VP9

Affected Products

Surrealdb