CVE-2026-7826
Deferred Deferred - Pending Action

Heap-based Out-of-Bounds Read in FalkorDB

Vulnerability report for CVE-2026-7826, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: securin

Description

A heap-based out-of-bounds read in the BufferSerializerIOv2_ReadBuffer function (src/serializers/serializer_io.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or disclose heap memory by supplying a crafted RDB stream whose sub-buffer length field exceeds the remaining buffer size. The only bounds check is an ASSERT(), which is compiled out in release builds, so memcpy() reads past the end of the heap allocation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
FalkorDB FalkorDB 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap-based out-of-bounds read vulnerability in FalkorDB's BufferSerializerIOv2_ReadBuffer function. It occurs when a remote attacker sends crafted Redis replication commands with a malformed RDB stream. The function lacks proper runtime bounds checks, relying only on ASSERT macros that are removed in release builds. This allows memcpy to read past the allocated heap memory when a sub-buffer length field exceeds the remaining buffer size.

Detection Guidance

This vulnerability involves a heap-based out-of-bounds read in FalkorDB's BufferSerializerIOv2_ReadBuffer function when processing malformed RDB streams. Detection requires monitoring for crashes or memory corruption during Redis replication operations. Check FalkorDB logs for errors related to buffer validation failures or heap corruption during RDB file processing.

Impact Analysis

An attacker could exploit this to cause a denial of service by crashing the FalkorDB instance. Additionally, they might read sensitive heap memory, potentially exposing confidential data stored in memory. The vulnerability requires the attacker to have network access to issue Redis replication commands, such as against an unprotected instance.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it is a technical implementation issue in FalkorDB's serializer function. However, if exploited, it could lead to denial of service or memory disclosure, which may indirectly impact data integrity and availability requirements under these regulations. Organizations using affected versions should assess operational risks and apply the patch to maintain compliance.

Mitigation Strategies

Upgrade FalkorDB to version 4.18.4 or later, which includes runtime bounds checks to prevent heap out-of-bounds reads. Ensure Redis instances are not configured with weak or no authentication to reduce exposure to malicious replication commands.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-7826. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart