SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clients can execute queries with ORDER BY rand() to tr…
Medium CVSS 6.5
Summary
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clients can execute queries with ORDER BY rand() to trigger a panic in the sorting function, crashing the server.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-m52v-24p8-654f
- https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-rand-sorting
Timeline
- nvd_ingest NVD