Double Free and Use-After-Free Vulnerability in FalkorDB
CVE-2026-5759

9.3CRITICAL

Key Information:

Vendor

Falkordb

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-5759?

A vulnerability in the RdbLoadDeletedNodes function of FalkorDB allows for a double free and use-after-free scenario. An attacker capable of issuing Redis replication commands can exploit this by sending a specially crafted RDB stream. This exploit can lead to a denial of service or even allow arbitrary code execution within the redis-server process. The vulnerability occurs because the length check is based on an assertion that is omitted in release builds, enabling the function to improperly handle memory, leading to multiple frees of the same memory buffer.

Affected Version(s)

FalkorDB 0 < 4.18.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.