Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-63737

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression trees, causing stack overflow during query processing and aborting the entire process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 26.2%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-63737


Contact Us

Shodan ® - All rights reserved