๐Ÿ” CVE Alert

CVE-2026-7827

HIGH 8.1

Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in crafted RDB

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

A stack-based buffer overflow in the _RdbLoadEntity function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service and possibly execute arbitrary code by supplying a crafted RDB stream with an attacker-controlled entity property count. The count sizes two variable-length arrays on the thread stack with no upper bound, and the decoder then fills them with attacker-supplied values.

CWE CWE-121
Vendor falkordb
Product falkordb
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for falkordb falkordb

Be the first to know when new high vulnerabilities affecting falkordb falkordb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

FalkorDB / FalkorDB
0 < 4.18.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/FalkorDB/FalkorDB/pull/1973 github.com: https://github.com/FalkorDB/FalkorDB/commit/7d15431aadf37588fadc2578b90c3afb5e8daa94 github.com: https://github.com/FalkorDB/FalkorDB/releases/tag/v4.18.4

Credits

Arjun Basnet from Securin