CVE-2026-7826: falha de alta gravidade em FalkorDB
Heap out-of-bounds read in FalkorDB BufferSerializerIOv2_ReadBuffer via crafted RDB
Publicada em
18Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.8
probabilidade de exploração
—
exploração observada
nãonenhuma fonte reporta
A heap-based out-of-bounds read in the BufferSerializerIOv2_ReadBuffer function (src/serializers/serializer_io.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or disclose heap memory by supplying a crafted RDB stream whose sub-buffer length field exceeds the remaining buffer size. The only bounds check is an ASSERT(), which is compiled out in release builds, so memcpy() reads past the end of the heap allocation.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
Produtos afetados
FalkorDB · FalkorDBCVEs relacionadas — FalkorDB
No mesmo produto, das mais perigosas para as menos.
CVE-2026-107911HIGHType confusion in FalkorDB GRAPH.QUERY via the --bolt argumentEPSS —CVE-2026-107910CRITICALAuthentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handlingEPSS —CVE-2026-107909HIGHPre-authentication heap out-of-bounds write in FalkorDB Bolt WebSocket frame handling via unbounded payload lengthEPSS —CVE-2026-107908CRITICALPre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET messageEPSS —CVE-2026-7827CRITICALStack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in crafted RDBEPSS —CVE-2026-5759CRITICALDouble free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code execution via crafted RDBEPSS —