CVE-2025-71393
概要

SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenticated attackers can bypass the recursion limit by chaining native and JavaScript function calls to trigger infinite recursion and exhaust server memory.

公表日 2026年7月18日23:17
登録日 2026年7月19日4:18
最終更新日 2026年7月21日3:16
関連情報、対策とツール
共通脆弱性一覧