CVE-2026-107911
Deferred Deferred - Pending Action

Type Confusion in FalkorDB Leads to DoS

Vulnerability report for CVE-2026-107911, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: securin

Description

A type confusion vulnerability in the _read_flags function (src/commands/cmd_dispatcher.c) in FalkorDB before 4.20.0 allows a remote authenticated attacker who can run GRAPH.QUERY to cause a denial of service and possibly disclose or corrupt memory. The function accepts a --bolt argument from any client and casts the following command argument, a Redis string object, to a Bolt client structure without checking its origin; the result-set code then dereferences pointers read from that object. The argument is parsed even when the Bolt endpoint is disabled, so default configurations are affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
FalkorDB FalkorDB 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-843 The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a type confusion vulnerability in FalkorDB versions before 4.20.0. The _read_flags function in src/commands/cmd_dispatcher.c incorrectly casts a Redis string object to a Bolt client structure without verifying its origin. This allows a remote authenticated attacker to cause a denial of service and potentially disclose or corrupt memory by running GRAPH.QUERY with a --bolt argument, even when the Bolt endpoint is disabled.

Impact Analysis

If you use FalkorDB before version 4.20.0, an attacker could exploit this to crash the database, leak sensitive data, or corrupt memory. This could disrupt services relying on FalkorDB and potentially expose confidential information.

Mitigation Strategies

Upgrade FalkorDB to version 4.20.0 or later to address the type confusion vulnerability in the _read_flags function.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107911. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart