在 FalkorDB 4.20.0 版本之前,_read_flags 函数(位于 src/commands/cmd_dispatcher.c)中存在一个类型混淆漏洞。该漏洞允许能够执行 GRAPH.QUERY 的远程认证攻击者造成拒绝服务,并可能导致内存信息泄露或内存损坏。该函数接受来自任意客户端的 --bolt 参数,并将后续的命令参数(一个 Redis 字符串对象)强制转换为 Bolt 客户端结构体,而未对其来源进行任何验证。随后,结果集代码会从该对象中解引用指针。即使 Bolt 端点处于禁用状态,该参数仍会被
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-5759 | 9.8 CRITICAL | Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code executio |
| CVE-2026-107908 | 9.8 CRITICAL | Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET mes |
| CVE-2026-7826 | 9.1 CRITICAL | Heap out-of-bounds read in FalkorDB BufferSerializerIOv2_ReadBuffer via crafted RDB |
| CVE-2026-107909 | 9.1 CRITICAL | Pre-authentication heap out-of-bounds write in FalkorDB Bolt WebSocket frame handling via |
| CVE-2026-7827 | 8.1 HIGH | Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in cra |
| CVE-2026-107910 | 8.1 HIGH | Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling |
No comments yet