CVE-2026-107909
Deferred Deferred - Pending Action

Heap-based Out-of-Bounds Write in FalkorDB

Vulnerability report for CVE-2026-107909, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: securin

Description

A heap-based out-of-bounds write in the ws_read_frame function (src/bolt/ws.c) and the buffer_apply_mask function (src/bolt/buffer.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to cause a denial of service and possibly corrupt heap memory by sending a WebSocket frame with a 64-bit extended payload length to the Bolt port. The payload length is not bounded, and the only bounds check in buffer_apply_mask is an ASSERT(), which is compiled out in release builds, so the function XORs memory beyond the end of the receive buffer with the attacker-supplied mask key. Only deployments that enable the Bolt endpoint (BOLT_PORT, disabled by default) are affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
FalkorDB FalkorDB 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap-based out-of-bounds write vulnerability in FalkorDB versions before 4.20.0. It occurs in the ws_read_frame function in src/bolt/ws.c and the buffer_apply_mask function in src/bolt/buffer.c. A remote unauthenticated attacker can exploit this by sending a WebSocket frame with a 64-bit extended payload length to the Bolt port. The payload length is not properly bounded, and the buffer_apply_mask function lacks proper bounds checking, leading to memory corruption when it XORs memory beyond the receive buffer with the attacker's mask key.

Impact Analysis

This vulnerability can cause a denial of service by crashing the FalkorDB server. It may also corrupt heap memory, potentially leading to arbitrary code execution or other unintended behavior. Only systems with the Bolt endpoint enabled (BOLT_PORT) are affected, as it is disabled by default.

Mitigation Strategies

Disable the Bolt endpoint by setting BOLT_PORT to disabled or a non-standard port if not needed. Upgrade FalkorDB to version 4.20.0 or later to address the heap-based out-of-bounds write vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107909. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart