FalkorDB 4.18.4 版本之前的 RDB 图解码器(位于 )中的 函数存在一个基于栈的缓冲区溢出漏洞。该漏洞允许能够发送 Redis 复制命令的远程攻击者(例如,针对未配置密码的实例)通过提供包含攻击者控制的实体属性计数值的构造恶意 RDB 流,导致拒绝服务,并可能执行任意代码。 该属性计数值用于确定两个可变长度数组的大小,这些数组被分配在线程栈上,但缺乏上限约束。随后,解码器会用攻击者提供的值填充这些数组,从而引发栈缓冲区溢出。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-5759 | 9.8 CRITICAL | Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code executio |
| CVE-2026-107908 | 9.8 CRITICAL | Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET mes |
| CVE-2026-7826 | 9.1 CRITICAL | Heap out-of-bounds read in FalkorDB BufferSerializerIOv2_ReadBuffer via crafted RDB |
| CVE-2026-107909 | 9.1 CRITICAL | Pre-authentication heap out-of-bounds write in FalkorDB Bolt WebSocket frame handling via |
| CVE-2026-107910 | 8.1 HIGH | Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling |
| CVE-2026-107911 | 7.5 HIGH | Type confusion in FalkorDB GRAPH.QUERY via the --bolt argument |
No comments yet