CVE-2026-88408
Received Received - Intake

Stack Overflow in FalkorDB Redis Module

Vulnerability report for CVE-2026-88408, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: MITRE

Description

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stack overflow in FalkorDB (a Redis module) versions 4.20.1 to 4.20.4. It occurs in the _GetGroup() function located in the /ops/op_aggregate.c file. Attackers can exploit this by sending specially crafted input to cause a Denial of Service (DoS) condition.

Detection Guidance

To detect this vulnerability, monitor for crashes or abnormal termination of FalkorDB processes, particularly when handling aggregate operations. Check logs for stack overflow errors in the _GetGroup() function. No specific commands are provided in the context.

Impact Analysis

This vulnerability allows attackers to crash the FalkorDB service by sending malicious input, leading to service disruption. If FalkorDB is part of a critical infrastructure or application, this could result in downtime or loss of functionality.

Compliance Impact

This vulnerability causes a Denial of Service (DoS) via stack overflow, which may disrupt services handling sensitive data. GDPR requires ensuring data availability and security; a DoS could violate these principles. HIPAA mandates safeguards against disruptions affecting protected health information; this flaw may compromise compliance.

Mitigation Strategies

Upgrade FalkorDB to a version beyond v4.20.4 to address the stack overflow issue in the _GetGroup() function. Avoid processing untrusted inputs in vulnerable functions until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88408. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart