CVE-2026-63759
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Jul 20, 2026
Vendor
unknown
Description
SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deeply nested type annotations to exhaust server memory and crash the process.