Multiple High Severity Vulnerabilities Discovered in SurrealDB
ID: 73b13096-768c-5f57-9937-ddcde61115d2
STIX ID: report--73b13096-768c-5f57-9937-ddcde61115d2
Feed Name: ThreatCluster
Three high-severity vulnerabilities in SurrealDB were disclosed on July 18, 2026: CVE-2024-58362 enables unauthenticated execution of subqueries via the RPC API during SIGNIN/SIGNUP, CVE-2024-58366 is a format-string flaw that can lead to arbitrary memory access and potential code execution for scripting-privileged users, and CVE-2024-58368 allows server crashes via malformed HTTP requests; CVSS scores range from 7.5 to 8.8, no active exploitation has been confirmed, and affected organizations are advised to check for IOCs and apply mitigations or patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
