{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-58370","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-07-18T12:40:52.917Z","datePublished":"2026-07-18T13:10:09.658Z","dateUpdated":"2026-07-28T01:47:55.449Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-07-28T01:47:55.449Z"},"datePublic":"2024-01-17T00:00:00.000Z","title":"SurrealDB before 1.1.0 Uncontrolled Recursion Denial of Service","descriptions":[{"lang":"en","value":"SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms. Authorized attackers can submit queries with excessive nesting depth to cause stack overflow and crash the server."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Uncontrolled Recursion","cweId":"CWE-674","type":"CWE"}]}],"affected":[{"vendor":"surrealdb","product":"surrealdb","defaultStatus":"unaffected","packageURL":"pkg:cargo/surrealdb","versions":[{"version":"0","status":"affected","versionType":"semver","lessThan":"1.1.0"},{"version":"1.1.0","status":"unaffected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.0"}]}]}],"metrics":[{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"}},{"format":"CVSS","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}],"references":[{"url":"https://github.com/surrealdb/surrealdb/security/advisories/GHSA-6r8p-hpg7-825g","name":"GitHub Security Advisory (GHSA-6r8p-hpg7-825g)","tags":["vendor-advisory"]},{"name":"VulnCheck Advisory: SurrealDB before 1.1.0 Uncontrolled Recursion Denial of Service","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/surrealdb-before-uncontrolled-recursion-denial-of-service"}],"x_generator":{"engine":"vulncheck-endgame"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-22T18:55:25.400478Z","id":"CVE-2024-58370","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-22T18:55:33.732Z"}}]}}