SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send a malformed WebSocket message to the /rpc endpoint to crash the server process.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
SurrealDB versions before 3.1.0 contain a critical denial of service vulnerability in the RPC handler that crashes the server when a WebSocket message sets the database parameter without specifying a namespace. This vulnerability is particularly concerning because it requires no authentication—an unauthenticated attacker can send a single malformed message to the /rpc endpoint to instantly terminate the server process. Organizations running vulnerable SurrealDB instances, especially those exposed to untrusted networks or the public internet, face immediate availability risks. The simplicity of exploitation means this vulnerability could be weaponized for service disruption attacks with minimal technical sophistication, making patch deployment urgent for affected deployments.
While this CVE lacks mapped MITRE ATT&CK techniques, Casky's platform would help practitioners detect the underlying attack patterns through behavioral analysis of WebSocket traffic and exception handling flows. Using Claude AI with extended reasoning across Casky's 754 security skills, practitioners would identify anomalous RPC requests that lack proper namespace specification—a deviation from expected parameter validation patterns. The platform would flag the transition from normal service operation to an unhandled panic condition, mapping this to broader denial of service attack patterns and resource exhaustion behaviors. Security teams would receive actionable findings highlighting the specific RPC parameter combinations that trigger crashes, enabling them to implement input validation controls, rate limiting on the /rpc endpoint, and authentication barriers before applying the 3.1.0 patch.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-63747. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation