CVE-2026-107908
Deferred Deferred - Pending Action

Heap-based Out-of-Bounds Write in FalkorDB

Vulnerability report for CVE-2026-107908, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: securin

Description

A heap-based out-of-bounds write in the BoltReadHandler function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to cause a denial of service and possibly execute arbitrary code by sending a Bolt RESET message with an attacker-chosen chunk size to the Bolt port. The handler checks the size only with ASSERT(), which is compiled out in release builds, then computes a destination pointer from the wire-supplied 16-bit size and moves buffered data up to about 64 KiB backwards past the start of the read buffer. Only deployments that enable the Bolt endpoint (BOLT_PORT, disabled by default) are affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
FalkorDB FalkorDB 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a heap-based out-of-bounds write in the BoltReadHandler function of FalkorDB before version 4.20.0. An unauthenticated remote attacker can exploit it by sending a Bolt RESET message with a malicious chunk size to the Bolt port. The handler fails to properly validate the size in release builds, leading to data being written up to 64 KiB past the buffer's start. This can cause a denial of service or allow arbitrary code execution. The Bolt endpoint is disabled by default, so only systems with it enabled are affected.

Detection Guidance

Check if FalkorDB is running with Bolt protocol enabled by inspecting configuration files or process arguments. Look for open ports matching the Bolt port (default 7687) using commands like 'netstat -tulnp | grep 7687' or 'ss -tulnp | grep 7687'. If Bolt is enabled, monitor for unexpected network traffic or crashes.

Impact Analysis

If you run FalkorDB with the Bolt endpoint enabled, an attacker could crash the database or execute arbitrary code by sending a specially crafted message. This could lead to data corruption, service disruption, or unauthorized access to sensitive information. Systems without the Bolt endpoint enabled are not affected.

Mitigation Strategies

Upgrade FalkorDB to version 4.20.0 or later where Bolt support has been removed. If upgrading is not possible, disable the Bolt endpoint by setting BOLT_PORT to disabled or removing Bolt-related configurations. Block the Bolt port (7687) at the firewall level if the endpoint must remain disabled.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107908. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart