Type Confusion Vulnerability in FalkorDB Prior to Version 4.20.0
CVE-2026-107911
7.7HIGH
What is CVE-2026-107911?
A type confusion vulnerability exists in the _read_flags function of FalkorDB prior to version 4.20.0. This flaw allows remote authenticated attackers who can execute GRAPH.QUERY commands to potentially trigger a denial of service condition or even disclose or corrupt memory. The issue arises because the function improperly casts a Redis string object into a Bolt client structure without validating its origin. Furthermore, the parsing of this command argument occurs even when the Bolt endpoint is disabled, impacting default configurations and increasing the risk of exploitation.
Affected Version(s)
FalkorDB 0 < 4.20.0
