Buffer Overflow Vulnerability in FalkorDB Redis Graph Decoders
CVE-2026-7827

9.2CRITICAL

Key Information:

Vendor

Falkordb

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-7827?

A stack-based buffer overflow vulnerability exists in the _RdbLoadEntity function of the Redis graph decoders in FalkorDB prior to version 4.18.4. This flaw allows a remote attacker, particularly against an unsecured instance, to trigger a denial of service or potentially execute arbitrary code. The attacker can exploit this vulnerability by sending a crafted RDB stream with a maliciously controlled entity property count, which leads to the allocation of oversized arrays on the thread stack without proper bounds checking, enabling the insertion of attacker-supplied values.

Affected Version(s)

FalkorDB 0 < 4.18.4

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.