Buffer Overflow Vulnerability in FalkorDB Redis Graph Decoders
CVE-2026-7827
9.2CRITICAL
What is CVE-2026-7827?
A stack-based buffer overflow vulnerability exists in the _RdbLoadEntity function of the Redis graph decoders in FalkorDB prior to version 4.18.4. This flaw allows a remote attacker, particularly against an unsecured instance, to trigger a denial of service or potentially execute arbitrary code. The attacker can exploit this vulnerability by sending a crafted RDB stream with a maliciously controlled entity property count, which leads to the allocation of oversized arrays on the thread stack without proper bounds checking, enabling the insertion of attacker-supplied values.
Affected Version(s)
FalkorDB 0 < 4.18.4
