OSV 1.4.0 · github-reviewed · 修改于 2026-07-02 04:03
发布时间
2026-07-02 04:03
GitHub 审查时间
2026-07-02 04:03
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/07/GHSA-q729-696q-g9pq/GHSA-q729-696q-g9pq.json
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested {, [, or ( tokens. The expression parser already enforced the limit for these tokens; the value/JSON parser omitted it. An unauthenticated attacker could send a deeply nested JSON payload to the WebSocket /rpc endpoint and exhaust server memory, crashing the process.
This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path.
An unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required.
A patch enforces the configured recursion depth limit in parse_value and parse_json, bringing them in line with the rest of the parser.
Restrict network access to the WebSocket /rpc endpoint to trusted clients.