CVE-2025-71395
EUVD-2025-21048618.07.2026, 14:17
SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to restrict resulting string length when using regex patterns. An authenticated attacker can craft a malicious query to exhaust server memory through unbounded string allocations, causing denial of service.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| surrealdb | surrealdb | 𝑥 < 2.0.5 |
| surrealdb | surrealdb | 2.1.0 ≤ 𝑥 < 2.1.5 |
| surrealdb | surrealdb | 2.2.0 ≤ 𝑥 < 2.2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration