CVE-2026-88406
Received Received - Intake

Stack Overflow in FalkorDB Redis Module

Vulnerability report for CVE-2026-88406, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: MITRE

Description

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
falkordb falkordb From 4.20.1 (inc) to 4.20.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

FalkorDB versions 4.20.1 to 4.20.4 contain a stack overflow vulnerability in the _ValidateUnion_Clauses function located in the ast_validations.c file. This flaw allows attackers to trigger a Denial of Service (DoS) condition by sending specially crafted input to the system.

Detection Guidance

This vulnerability is specific to FalkorDB and involves a stack overflow in the _ValidateUnion_Clauses function. Detection requires checking the FalkorDB version running on your system. If you are running versions v4.20.1 to v4.20.4, the system is vulnerable. Use the command 'redis-cli info modules' to check the installed FalkorDB version.

Impact Analysis

This vulnerability can cause your FalkorDB instance to crash or become unresponsive, leading to service disruption. Since it is a DoS issue, attackers could exploit it to take down your database server by sending malicious queries, affecting availability of your application or service.

Compliance Impact

This vulnerability causes a Denial of Service (DoS) via stack overflow, which could disrupt services handling sensitive data. For GDPR, this may impact availability of personal data processing systems. For HIPAA, it could affect the integrity and availability of protected health information systems. Compliance may require mitigating such vulnerabilities to ensure continuous protection of regulated data.

Mitigation Strategies

Upgrade FalkorDB to a version that fixes the stack overflow issue in _ValidateUnion_Clauses. Specifically, update to a version beyond v4.20.4 to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88406. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart