Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade FalkorDB to version 4.18.4 or later.
Vendor Workaround
Require authentication on the Redis/FalkorDB instance (requirepass or ACLs), restrict or rename the REPLICAOF/SLAVEOF commands so untrusted clients cannot use them, and do not expose the instance to untrusted networks.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow in the _RdbLoadEntity function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service and possibly execute arbitrary code by supplying a crafted RDB stream with an attacker-controlled entity property count. The count sizes two variable-length arrays on the thread stack with no upper bound, and the decoder then fills them with attacker-supplied values. | |
| Title | Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in crafted RDB | |
| First Time appeared |
Falkordb
Falkordb falkordb |
|
| Weaknesses | CWE-121 | |
| CPEs | cpe:2.3:a:falkordb:falkordb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Falkordb
Falkordb falkordb |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: securin
Published:
Updated: 2026-10-09T04:04:29.094Z
Reserved: 2026-05-05T02:50:42.544Z
Link: CVE-2026-7827
No data.
Status : Deferred
Published: 2026-10-09T05:16:45.327
Modified: 2026-10-09T05:16:45.447
Link: CVE-2026-7827
No data.
OpenCVE Enrichment
Updated: 2026-10-09T07:00:10Z
-
CWE-121
Stack-based Buffer Overflow