Beveiligingsadvies

CVE-2026-63750

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-20 12:04:42
Laatst bijgewerkt 2026-07-28 01:05:43
Toegewezen door VulnCheck
CVSS-score 6.9
Status PUBLISHED

Beschrijving

SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer. Attackers can stream WebSocket frames larger than the configured limit across multiple concurrent connections to consume excessive memory and degrade /sql availability.