CVE-2025-71395
surrealdb surrealdb 취약점
SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to restrict resulting string length when using regex patterns. An authenticated attacker can craft a malicious query to exhaust server memory through unbounded string allocations, causing denial of service.
- 대응 우선순위
- 점검
- CVSS
- 7.1
- EPSS
- 0.24% 백분위 14.5% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.18