Heap-Based Out-of-Bounds Read Vulnerability in FalkorDB Product from Vendor FalkorDB
CVE-2026-7826
8.8HIGH
What is CVE-2026-7826?
A vulnerability in the BufferSerializerIOv2_ReadBuffer function of FalkorDB allows for a heap-based out-of-bounds read, potentially leading to denial of service or disclosure of sensitive heap memory. This issue arises when a remote attacker sends crafted Redis replication commands aimed at unprotected instances. The lack of proper bounds checking in the release build—where an ASSERT() is removed—enables the memcpy() function to read beyond the end of allocated heap memory, exacerbating the risk of exploitation.
Affected Version(s)
FalkorDB 0 < 4.18.4
