CVE-2025-71391: SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send crafted HTTP
SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send crafted HTTP queries containing null bytes to the /sql endpoint, causing an unhandled exception that crashes the SurrealDB instance and any dependent applications.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-71391
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-713910.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-71391 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for SurrealDB
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-63763: SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation…nvd · 2026-07-20
- mediumCVE-2026-63762: SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability …nvd · 2026-07-20
- mediumCVE-2026-63761: SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is co…nvd · 2026-07-20
- highCVE-2026-63760: SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and …nvd · 2026-07-20
- mediumCVE-2026-63759: SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when pr…nvd · 2026-07-20
- mediumCVE-2026-63758: SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL stat…nvd · 2026-07-20
More from NVD Recent CVEs
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01
- mediumCVE-2026-67354: guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in Re…2026-08-01
- mediumCVE-2026-67353: guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the Cook…2026-08-01
- highCVE-2026-67352: luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_…2026-08-01
- mediumCVE-2026-67344: ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYP…2026-08-01