---
id: CVE-2024-58358
title: >-
  SurrealDB versions before 2.1.0 contain a denial of service vulnerability in
  role conversion that allows privileged owner users to define users with
  nonexistent roles
summary: >-
  SurrealDB versions before 2.1.0 contain a denial of service vulnerability in
  role conversion that allows privileged owner users to define users with
  nonexistent roles. Attackers can trigger an uncaught panic by signing in with
  a user ass…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-248
published: '2026-07-18'
updated: '2026-07-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58358'
references:
  - url: >-
      https://github.com/surrealdb/surrealdb/security/advisories/GHSA-jc55-246c-r88f
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-nonexistent-role
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-07-19T03:27:58.305Z'
epss: 0.00472
epssPercentile: 0.38126
---

## Overview

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
