Description
A stack-based buffer overflow in the _RdbLoadEntity function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service and possibly execute arbitrary code by supplying a crafted RDB stream with an attacker-controlled entity property count. The count sizes two variable-length arrays on the thread stack with no upper bound, and the decoder then fills them with attacker-supplied values.
Published: 2026-10-09
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A stack-based buffer overflow occurs in the _RdbLoadEntity function of FalkorDB’s RDB graph decoders. The vulnerability is triggered when a crafted RDB stream supplies an attacker-controlled property count, causing two unbounded variable‑length arrays to be allocated on the thread stack. The decoder then copies the attack data into these arrays, corrupting the stack. The overflow allows the attacker to cause a denial of service and potentially execute arbitrary code on the host.

Affected Systems

The flaw affects FalkorDB instances running any version earlier than 4.18.4, particularly those configured without password protection or restricted access. The issue surfaces when a remote attacker can issue Redis replication commands such as SLAVEOF/REPLICAOF against the vulnerable server.

Risk and Exploitability

The CVSS score of 9.2 indicates a critical severity level. Although EPSS data is not available, the absence of authentication and exposure to untrusted networks make exploitation highly probable. The vulnerability is listed in no CISA KEV catalog yet still represents a high‑risk attack vector, as an attacker with network access can directly trigger the buffer overflow via standard replication commands.

Generated by OpenCVE AI on October 9, 2026 at 05:22 UTC.

Remediation

Vendor Solution

Upgrade FalkorDB to version 4.18.4 or later.


Vendor Workaround

Require authentication on the Redis/FalkorDB instance (requirepass or ACLs), restrict or rename the REPLICAOF/SLAVEOF commands so untrusted clients cannot use them, and do not expose the instance to untrusted networks.


OpenCVE Recommended Actions

  • Upgrade FalkorDB to 4.18.4 or later
  • Configure authentication on the instance (requirepass or ACLs)
  • Restrict or rename the REPLICAOF/SLAVEOF commands so untrusted clients cannot use them
  • Do not expose the instance to untrusted networks

Generated by OpenCVE AI on October 9, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow in the _RdbLoadEntity function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service and possibly execute arbitrary code by supplying a crafted RDB stream with an attacker-controlled entity property count. The count sizes two variable-length arrays on the thread stack with no upper bound, and the decoder then fills them with attacker-supplied values.
Title Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in crafted RDB
First Time appeared Falkordb
Falkordb falkordb
Weaknesses CWE-121
CPEs cpe:2.3:a:falkordb:falkordb:*:*:*:*:*:*:*:*
Vendors & Products Falkordb
Falkordb falkordb
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Falkordb Falkordb
cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-09T16:47:46.031Z

Reserved: 2026-05-05T02:50:42.544Z

Link: CVE-2026-7827

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T05:16:45.327

Modified: 2026-10-09T05:16:45.447

Link: CVE-2026-7827

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T07:00:10Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow