Impact
The flaw resides in the error handling logic of the GRAPH.EFFECT component within the FalkorDB Redis module (v4.20.1). When malformed or unexpected input is processed, the error path fails to recover, causing the module to refuse further commands and effectively halt service for legitimate users, which amounts to a denial of service.
Affected Systems
Any deployment running FalkorDB version 4.20.1 is affected. No other vendors or product lines are listed in the CNA data.
Risk and Exploitability
The CVSS score of 7.5 indicates a medium‑high severity vulnerability. The EPSS score is not available, so the likelihood of exploitation remains uncertain. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could trigger the flaw by sending specially crafted commands to the Redis instance, potentially leveraging the module’s exposed graph effect functionality. No authentication requirement is explicitly documented; the attack vector is inferred to be remote via the Redis protocol.
OpenCVE Enrichment