CVE-2026-88407
7.5FalkorDB · FalkorDB (Redis module)
A vulnerability in the FalkorDB Redis module allows unauthenticated attackers to trigger a denial of service through an out-of-bounds read error.
Executive summary
An out-of-bounds read vulnerability in the FalkorDB Redis module enables unauthenticated remote attackers to cause a denial of service, potentially disrupting critical database operations.
Vulnerability
This vulnerability is an out-of-bounds read flaw within the node_token_count and relation_token_count components. It can be triggered by an unauthenticated attacker sending a crafted input to the database module.
Business impact
The ability for an unauthenticated attacker to remotely force a denial of service presents a significant risk to availability. With a CVSS score of 7.5, this flaw could lead to unplanned downtime of database services, disrupting dependent applications and potentially resulting in operational paralysis for systems relying on FalkorDB for real-time data processing.
Remediation
Immediate Action: Monitor the official FalkorDB repository for the release of a security patch and apply it to all instances running versions 4.20.1 through 4.20.4 as soon as it becomes available.
Proactive Monitoring: Implement monitoring for abnormal Redis module crashes or unexpected service restarts, and review access logs for requests containing suspicious or malformed input patterns.
Compensating Controls: Restrict network access to the Redis instance to trusted IP addresses only, effectively limiting the attack surface to authorized segments until a patch is deployed.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high severity of this vulnerability, administrators should prioritize the mitigation of this risk by restricting network access to affected database modules. Organizations must remain vigilant for vendor updates and be prepared to deploy the fix immediately upon release to restore service stability and security.
More FalkorDB CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section