在 FalkorDB 4.20.0 版本之前, 文件中的 函数存在一个基于堆的越界写入漏洞。远程未认证的攻击者通过向 Bolt 端口发送包含攻击者自定义 chunk 大小的 Bolt RESET 消息,可导致拒绝服务(DoS),并可能执行任意代码。 该处理程序仅使用 宏对 chunk 大小进行检查,而 在发布版本(release builds)中会被编译移除。随后,该函数根据从网络传入的 16 位 size 字段计算目标指针,并将缓冲数据最多向前(向低地址方向)移动约 64 KiB,超出读取缓冲区的起始位置,从而引
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-5759 | 9.8 CRITICAL | Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code executio |
| CVE-2026-7826 | 9.1 CRITICAL | Heap out-of-bounds read in FalkorDB BufferSerializerIOv2_ReadBuffer via crafted RDB |
| CVE-2026-107909 | 9.1 CRITICAL | Pre-authentication heap out-of-bounds write in FalkorDB Bolt WebSocket frame handling via |
| CVE-2026-7827 | 8.1 HIGH | Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in cra |
| CVE-2026-107910 | 8.1 HIGH | Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling |
| CVE-2026-107911 | 7.5 HIGH | Type confusion in FalkorDB GRAPH.QUERY via the --bolt argument |
No comments yet