CVE-2026-7827
Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in crafted RDB
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
A stack-based buffer overflow in the _RdbLoadEntity function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service and possibly execute arbitrary code by supplying a crafted RDB stream with an attacker-controlled entity property count. The count sizes two variable-length arrays on the thread stack with no upper bound, and the decoder then fills them with attacker-supplied values.
| CWE | CWE-121 |
| Vendor | falkordb |
| Product | falkordb |
| Published | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for falkordb falkordb
Be the first to know when new high vulnerabilities affecting falkordb falkordb are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
FalkorDB / FalkorDB
0 < 4.18.4
References
Credits
Arjun Basnet from Securin