---
id: CVE-2024-58369
title: >-
  SurrealDB versions before 1.1.1 fail to properly validate invocation of custom
  parameters and functions at root or namespace levels, causing server panic
summary: >-
  SurrealDB versions before 1.1.1 fail to properly validate invocation of custom
  parameters and functions at root or namespace levels, causing server panic.
  Authorized clients can invoke these entities at unsupported levels to crash
  the Su…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-248
published: '2026-07-18'
updated: '2026-07-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58369'
references:
  - url: >-
      https://github.com/surrealdb/surrealdb/security/advisories/GHSA-jm4v-58r5-66hj
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-global-parameters
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-07-19T03:27:58.509Z'
epss: 0.0045
epssPercentile: 0.36608
---

## Overview

SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
