Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107908— Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET message

Quick assessment

Affected
FalkorDB FalkorDB
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 FalkorDB 4.20.0 版本之前, 文件中的 函数存在一个基于堆的越界写入漏洞。远程未认证的攻击者通过向 Bolt 端口发送包含攻击者自定义 chunk 大小的 Bolt RESET 消息,可导致拒绝服务(DoS),并可能执行任意代码。 该处理程序仅使用 宏对 chunk 大小进行检查,而 在发布版本(release builds)中会被编译移除。随后,该函数根据从网络传入的 16 位 size 字段计算目标指针,并将缓冲数据最多向前(向低地址方向)移动约 64 KiB,超出读取缓冲区的起始位置,从而引

CVSS 9.8 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107908

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET message
Source: CVE Program / CVE List V5
Vulnerability Description
A heap-based out-of-bounds write in the BoltReadHandler function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to cause a denial of service and possibly execute arbitrary code by sending a Bolt RESET message with an attacker-chosen chunk size to the Bolt port. The handler checks the size only with ASSERT(), which is compiled out in release builds, then computes a destination pointer from the wire-supplied 16-bit size and moves buffered data up to about 64 KiB backwards past the start of the read buffer. Only deployments that enable the Bolt endpoint (BOLT_PORT, disabled by default) are affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
FalkorDB FalkorDB 0 ~ 4.20.0 cpe:2.3:a:falkordb:falkordb:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-107908

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107908

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107908 (1)

Vendor Pages for CVE-2026-107908 (1)

Same Patch Batch · FalkorDB · 2026-10-09 · 7 CVEs total

CVE-2026-5759 9.8 CRITICAL Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code executio
CVE-2026-7826 9.1 CRITICAL Heap out-of-bounds read in FalkorDB BufferSerializerIOv2_ReadBuffer via crafted RDB
CVE-2026-107909 9.1 CRITICAL Pre-authentication heap out-of-bounds write in FalkorDB Bolt WebSocket frame handling via
CVE-2026-7827 8.1 HIGH Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in cra
CVE-2026-107910 8.1 HIGH Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling
CVE-2026-107911 7.5 HIGH Type confusion in FalkorDB GRAPH.QUERY via the --bolt argument

IV. Related Vulnerabilities

V. Comments for CVE-2026-107908

No comments yet


Leave a comment