{"id":"CVE-2024-58369","title":"SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic","summary":"SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the Su…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-248"],"published":"2026-07-18","updated":"2026-07-18","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-58369","references":[{"url":"https://github.com/surrealdb/surrealdb/security/advisories/GHSA-jm4v-58r5-66hj","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-global-parameters","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-07-19T03:27:58.509Z","epss":0.0045,"epssPercentile":0.38383,"slug":"CVE-2024-58369","body":"## Overview\n\nSurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}