Heap-Based Out-of-Bounds Write Vulnerability in FalkorDB
CVE-2026-107908

9.3CRITICAL

Key Information:

Vendor

Falkordb

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107908?

A vulnerability exists in FalkorDB that allows an unauthenticated remote attacker to exploit the BoltReadHandler function, leading to potential denial of service and arbitrary code execution. By sending a specially crafted Bolt RESET message with a malicious chunk size to the Bolt port, the attacker can manipulate destination memory pointers, causing buffer overflows. The vulnerability lies in the inadequate size checks during the handling of incoming requests, particularly because assertion checks are omitted in the release version. Only systems with the Bolt endpoint enabled, which is disabled by default, are susceptible to this issue. Users are encouraged to upgrade to FalkorDB version 4.20.0 or later to mitigate risks associated with this vulnerability.

Affected Version(s)

FalkorDB 0 < 4.20.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.