CVE-2026-7827
Deferred Deferred - Pending Action

Stack-Based Buffer Overflow in FalkorDB

Vulnerability report for CVE-2026-7827, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: securin

Description

A stack-based buffer overflow in the _RdbLoadEntity function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service and possibly execute arbitrary code by supplying a crafted RDB stream with an attacker-controlled entity property count. The count sizes two variable-length arrays on the thread stack with no upper bound, and the decoder then fills them with attacker-supplied values.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
FalkorDB FalkorDB 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-7827 is a stack-based buffer overflow in FalkorDB's RDB graph decoders. It occurs in the _RdbLoadEntity function where attacker-controlled property counts from RDB streams are used to size variable-length arrays on the thread stack without upper bounds. This can cause stack overflow, leading to denial of service or arbitrary code execution if an attacker sends a crafted RDB stream with a large property count.

Detection Guidance

This vulnerability can be detected by checking the version of FalkorDB in use. If your system runs FalkorDB versions before 4.18.4, it is vulnerable. Use commands like 'redis-cli info server' to check the version or inspect the FalkorDB installation directory for version details.

Impact Analysis

If you run a FalkorDB instance with no password configured, a remote attacker could exploit this to crash your database or execute arbitrary code by sending a specially crafted RDB stream. This could disrupt services relying on FalkorDB or allow unauthorized access to data or system resources.

Compliance Impact

This vulnerability could lead to denial of service or arbitrary code execution, which may result in unauthorized data access or processing disruptions. Such incidents could violate GDPR's integrity and availability principles or HIPAA's security requirements for protecting health data.

Mitigation Strategies

Upgrade FalkorDB to version 4.18.4 or later immediately. This version includes fixes for the stack-based buffer overflow by replacing variable-length stack arrays with bounded heap allocations and adding upper bound checks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-7827. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart