NULL Pointer Dereference Affecting surrealdb package, versions <2.6.1>=3.0.0-alpha.8 <3.0.0-beta.3


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.25% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUST-SURREALDB-18307372
  • published25 Jul 2026
  • disclosed20 Jul 2026
  • creditUnknown

Introduced: 20 Jul 2026

NewCVE-2026-63762  (opens in a new tab)
CWE-476  (opens in a new tab)

How to fix?

Upgrade surrealdb to version 2.6.1, 3.0.0-beta.3 or higher.

Overview

Affected versions of this package are vulnerable to NULL Pointer Dereference in the embedded JavaScript scripting engine when the --allow-scripting capability is enabled. An attacker can cause the server process to terminate immediately without graceful shutdown by constructing a large string using built-in string functions and passing it to the JavaScript runtime for compilation, which triggers a null pointer dereference in the underlying QuickJS-NG engine. This is only exploitable if the --allow-scripting capability is enabled and the attacker is able to execute arbitrary queries, including unauthenticated guests when --allow-guests is enabled.

CVSS Base Scores

version 4.0
version 3.1