Description
A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.1 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or execute arbitrary code in the redis-server process by supplying a crafted RDB stream whose deleted-nodes buffer length is not a multiple of sizeof(NodeID). The length check relies on ASSERT(), which is compiled out in release builds, so the function continues after freeing the buffer, reading it and freeing it a second time.
Published: 2026-10-09
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw is a double free followed by a use‑after‑free in FalkorDB’s RdbLoadDeletedNodes Graph decoder. A malicious RDB stream whose deleted‑nodes buffer length is not a multiple of the NodeID size bypasses a length check that relies on an assert removed from release builds. The function therefore frees the buffer, continues to read it, and frees it again, allowing a remote attacker to trigger a denial of service or execute arbitrary code within the redis-server process.

Affected Systems

Affected software is FalkorDB, any deployment running a version prior to 4.18.1. The vulnerability is tied to the graph decoding logic in that product and is not limited to a particular platform. The provided CPE indicates all variants of FalkorDB are impacted, and the advisory advises upgrading to 4.18.1 or later.

Risk and Exploitability

The CVSS score is 9.3, indicating a critical severity. No EPSS score is available, but the vulnerability is not listed in CISA’s KEV catalog. The exploit requires an attacker who can issue Redis replication commands against an unprotected instance, so the attack vector is remote over the network to an unauthenticated service. Because the flaw resides in core decoding code that runs during normal replication, a successful exploit would allow control of the server process if an attacker can supply a crafted RDB payload, making the risk high for exposed or insecure instances.

Generated by OpenCVE AI on October 9, 2026 at 05:22 UTC.

Remediation

Vendor Solution

Upgrade FalkorDB to version 4.18.1 or later.


Vendor Workaround

Require authentication on the Redis/FalkorDB instance (requirepass or ACLs), restrict or rename the REPLICAOF/SLAVEOF commands so untrusted clients cannot use them, and do not expose the instance to untrusted networks.


OpenCVE Recommended Actions

  • Upgrade FalkorDB to version 4.18.1 or a later release that contains the fix.
  • Configure authentication on the FalkorDB instance using requirepass or ACLs to prevent unauthenticated clients from issuing replication commands.
  • Restrict or rename the REPLICAOF/SLAVEOF commands so that untrusted clients cannot use them, and ensure the instance is not exposed to untrusted networks.

Generated by OpenCVE AI on October 9, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.1 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or execute arbitrary code in the redis-server process by supplying a crafted RDB stream whose deleted-nodes buffer length is not a multiple of sizeof(NodeID). The length check relies on ASSERT(), which is compiled out in release builds, so the function continues after freeing the buffer, reading it and freeing it a second time.
Title Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code execution via crafted RDB
First Time appeared Falkordb
Falkordb falkordb
Weaknesses CWE-415
CWE-416
CPEs cpe:2.3:a:falkordb:falkordb:*:*:*:*:*:*:*:*
Vendors & Products Falkordb
Falkordb falkordb
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Falkordb Falkordb
cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-09T04:04:28.078Z

Reserved: 2026-04-07T17:26:12.107Z

Link: CVE-2026-5759

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T05:16:44.920

Modified: 2026-10-09T05:16:45.043

Link: CVE-2026-5759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T07:30:17Z

Weaknesses