CVE-2026-63750
EUVD-2026-4592120.07.2026, 12:19
SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer. Attackers can stream WebSocket frames larger than the configured limit across multiple concurrent connections to consume excessive memory and degrade /sql availability.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.