在 FalkorDB 4.20.0 版本之前, 中的 函数以及 中的 函数存在一个基于堆的越界写入漏洞。远程未认证攻击者可以通过向 Bolt 端口发送一个带有 64 位扩展负载长度的 WebSocket 帧,导致服务拒绝(DoS)并可能破坏堆内存。 负载长度未受到限制,而 中唯一的边界检查是一个 宏,该宏在发布版本(release builds)中会被编译移除。因此,该函数会将接收缓冲区末尾之外的内存与攻击者提供的掩码密钥进行 XOR 运算。只有启用了 Bolt 端口的部署实例(默认情况下 是禁用的)会受到此漏洞影
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-5759 | 9.8 CRITICAL | Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code executio |
| CVE-2026-107908 | 9.8 CRITICAL | Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET mes |
| CVE-2026-7826 | 9.1 CRITICAL | Heap out-of-bounds read in FalkorDB BufferSerializerIOv2_ReadBuffer via crafted RDB |
| CVE-2026-7827 | 8.1 HIGH | Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in cra |
| CVE-2026-107910 | 8.1 HIGH | Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling |
| CVE-2026-107911 | 7.5 HIGH | Type confusion in FalkorDB GRAPH.QUERY via the --bolt argument |
No comments yet