CVE-2026-5759
Deferred Deferred - Pending Action

Double Free and Use-After-Free in FalkorDB

Vulnerability report for CVE-2026-5759, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: securin

Description

A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.1 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or execute arbitrary code in the redis-server process by supplying a crafted RDB stream whose deleted-nodes buffer length is not a multiple of sizeof(NodeID). The length check relies on ASSERT(), which is compiled out in release builds, so the function continues after freeing the buffer, reading it and freeing it a second time.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
FalkorDB FalkorDB 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CWE-415 The product calls free() twice on the same memory address.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-5759 is a double free and use-after-free vulnerability in FalkorDB's RDB graph decoders. It occurs in the RdbLoadDeletedNodes function when processing a crafted RDB stream where the deleted-nodes buffer length is not a multiple of sizeof(NodeID). The vulnerability relies on ASSERT() statements that are compiled out in release builds, allowing execution to continue after freeing memory, leading to a second free or arbitrary code execution.

Detection Guidance

This vulnerability can be detected by checking the FalkorDB version in use. If your system runs a version prior to 4.18.1, it is vulnerable. Use commands like 'redis-cli INFO server' to check the FalkorDB version or inspect the release tags in the FalkorDB repository.

Impact Analysis

This vulnerability allows a remote attacker who can issue Redis replication commands to cause a denial of service or execute arbitrary code in the redis-server process. It specifically targets instances with no password configured, making unprotected Redis servers vulnerable to exploitation.

Compliance Impact

This vulnerability could lead to denial of service or arbitrary code execution in Redis-server processes, potentially compromising data integrity and availability. Such disruptions may violate compliance requirements under GDPR (data availability) and HIPAA (system integrity and availability), depending on the affected system's role in processing regulated data.

Mitigation Strategies

Upgrade FalkorDB to version 4.18.1 or later immediately. This version includes fixes for the double free and use-after-free vulnerabilities in the RDB serializer. Ensure no Redis replication commands are exposed without authentication to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5759. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart