This advisory has been withdrawn because it is a duplicate of GHSA-jc55-246c-r88f. This link is maintained to preserve external references.
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server.
{
"cwe_ids": [
"CWE-248"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-04T19:18:07Z",
"nvd_published_at": "2026-07-18T14:17:08Z",
"severity": "MODERATE"
}