logo

Multiple High Severity Vulnerabilities Discovered in SurrealDB

ID: 73b13096-768c-5f57-9937-ddcde61115d2

STIX ID: report--73b13096-768c-5f57-9937-ddcde61115d2

Feed Name: ThreatCluster

Threat Score
65/100

Date Published: 2026-07-18

Date Updated: 2026-07-21

...
...

Three high-severity vulnerabilities in SurrealDB were disclosed on July 18, 2026: CVE-2024-58362 enables unauthenticated execution of subqueries via the RPC API during SIGNIN/SIGNUP, CVE-2024-58366 is a format-string flaw that can lead to arbitrary memory access and potential code execution for scripting-privileged users, and CVE-2024-58368 allows server crashes via malformed HTTP requests; CVSS scores range from 7.5 to 8.8, no active exploitation has been confirmed, and affected organizations are advised to check for IOCs and apply mitigations or patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.