在 FalkorDB 4.18.4 版本之前,BufferSerializerIOv2_ReadBuffer 函数(位于 src/serializers/serializer_io.c)中存在一个基于堆的越界读取漏洞。远程攻击者如果能够发送 Redis 复制命令(例如,针对未配置密码的实例),可以通过提供经过精心构造的 RDB 数据流来触发该漏洞,其中子缓冲区长度字段超过了剩余缓冲区的大小,从而导致拒绝服务或堆内存信息泄露。唯一的边界检查是一个 ASSERT() 宏,在发布构建版本中会被编译掉,因此 memcpy(
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-5759 | 9.8 CRITICAL | Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code executio |
| CVE-2026-107908 | 9.8 CRITICAL | Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET mes |
| CVE-2026-107909 | 9.1 CRITICAL | Pre-authentication heap out-of-bounds write in FalkorDB Bolt WebSocket frame handling via |
| CVE-2026-7827 | 8.1 HIGH | Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in cra |
| CVE-2026-107910 | 8.1 HIGH | Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling |
| CVE-2026-107911 | 7.5 HIGH | Type confusion in FalkorDB GRAPH.QUERY via the --bolt argument |
No comments yet