CVE-2026-63750
EUVD-2026-4592120.07.2026, 12:19
SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer. Attackers can stream WebSocket frames larger than the configured limit across multiple concurrent connections to consume excessive memory and degrade /sql availability.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| surrealdb | surrealdb | 𝑥 < 3.1.0 |
𝑥
= Vulnerable software versions