SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenticated attackers can send crafted HTTP requests with malformed header values to trigger an uncaught exception that crashes the server.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
SurrealDB versions before 1.1.0 contain a critical input validation flaw in their HTTP REST API implementation. The vulnerability stems from improper parsing of the ID, DB, and NS headers when they contain special characters, allowing unauthenticated attackers to crash the server by sending malformed requests. This affects any organization deploying vulnerable SurrealDB instances, particularly those exposing the REST API to untrusted networks. The vulnerability is especially concerning because it requires no authentication, making it accessible to anyone with network access to the API endpoint.
While this CVE doesn't map to specific MITRE ATT&CK techniques, Casky's approach would focus practitioners on detecting the attack surface through input validation and exception handling analysis. Using Claude AI's extended reasoning capabilities, security teams would identify the underlying weakness: insufficient sanitization of HTTP headers before processing. Practitioners working with Casky would recognize this pattern as part of broader CWE-248 (Uncaught Exception) weaknesses and correlate similar parsing vulnerabilities across their infrastructure. Although no specific ATT&CK techniques apply here, the practical defense involves monitoring for repeated malformed API requests, implementing strict input validation on header values, and maintaining strict version control—all areas where AI-assisted security analysis helps teams identify vulnerable configurations before exploitation occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2024-58368. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation