Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-63760

SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated attackers can send deeply nested JSON payloads to the WebSocket /rpc endpoint to exhaust server memory and crash the process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 28.4%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-63760


Contact Us

Shodan ® - All rights reserved