CVE-2026-88407
Received Received - Intake

Out-of-Bounds Read in FalkorDB Redis Module

Vulnerability report for CVE-2026-88407, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: MITRE

Description

An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
falkordb falkordb From 4.20.1 (inc) to 4.20.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds read vulnerability in FalkorDB, a Redis module. It exists in the node_token_count/relation_token_count component versions 4.20.1 to 4.20.4. The flaw allows attackers to cause a Denial of Service by providing specially crafted input that reads beyond allocated memory.

Detection Guidance

This vulnerability is specific to FalkorDB versions 4.20.1 to 4.20.4 and involves an out-of-bounds read in the node_token_count/relation_token_count component. Detection requires checking the installed version of FalkorDB and monitoring for crashes or errors related to token counting operations.

Impact Analysis

If exploited, this vulnerability can crash the FalkorDB service, leading to service disruption. Since FalkorDB is a Redis module, the Redis server may also become unavailable, affecting all dependent applications and services.

Compliance Impact

This vulnerability causes a Denial of Service (DoS) via out-of-bounds read, which could disrupt services handling sensitive data. For GDPR, this may impact availability of personal data processing systems. For HIPAA, it could affect the integrity and availability of protected health information systems. Compliance may be compromised if systems fail to maintain required uptime or data integrity due to DoS conditions.

Mitigation Strategies

Upgrade FalkorDB to a version beyond v4.20.4 to address the out-of-bounds read vulnerability in node_token_count/relation_token_count.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88407. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart