Heap-Based Out-of-Bounds Read Vulnerability in FalkorDB Product from Vendor FalkorDB
CVE-2026-7826

8.8HIGH

Key Information:

Vendor

Falkordb

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-7826?

A vulnerability in the BufferSerializerIOv2_ReadBuffer function of FalkorDB allows for a heap-based out-of-bounds read, potentially leading to denial of service or disclosure of sensitive heap memory. This issue arises when a remote attacker sends crafted Redis replication commands aimed at unprotected instances. The lack of proper bounds checking in the release build—where an ASSERT() is removed—enables the memcpy() function to read beyond the end of allocated heap memory, exacerbating the risk of exploitation.

Affected Version(s)

FalkorDB 0 < 4.18.4

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.