Impact
A stack-based buffer overflow occurs in the _RdbLoadEntity function of FalkorDB’s RDB graph decoders. The vulnerability is triggered when a crafted RDB stream supplies an attacker-controlled property count, causing two unbounded variable‑length arrays to be allocated on the thread stack. The decoder then copies the attack data into these arrays, corrupting the stack. The overflow allows the attacker to cause a denial of service and potentially execute arbitrary code on the host.
Affected Systems
The flaw affects FalkorDB instances running any version earlier than 4.18.4, particularly those configured without password protection or restricted access. The issue surfaces when a remote attacker can issue Redis replication commands such as SLAVEOF/REPLICAOF against the vulnerable server.
Risk and Exploitability
The CVSS score of 9.2 indicates a critical severity level. Although EPSS data is not available, the absence of authentication and exposure to untrusted networks make exploitation highly probable. The vulnerability is listed in no CISA KEV catalog yet still represents a high‑risk attack vector, as an attacker with network access can directly trigger the buffer overflow via standard replication commands.
OpenCVE Enrichment