Double Free and Use-After-Free Vulnerability in FalkorDB
CVE-2026-5759
9.3CRITICAL
What is CVE-2026-5759?
A vulnerability in the RdbLoadDeletedNodes function of FalkorDB allows for a double free and use-after-free scenario. An attacker capable of issuing Redis replication commands can exploit this by sending a specially crafted RDB stream. This exploit can lead to a denial of service or even allow arbitrary code execution within the redis-server process. The vulnerability occurs because the length check is based on an assertion that is omitted in release builds, enabling the function to improperly handle memory, leading to multiple frees of the same memory buffer.
Affected Version(s)
FalkorDB 0 < 4.18.1
