Description
A type confusion vulnerability in the _read_flags function (src/commands/cmd_dispatcher.c) in FalkorDB before 4.20.0 allows a remote authenticated attacker who can run GRAPH.QUERY to cause a denial of service and possibly disclose or corrupt memory. The function accepts a --bolt argument from any client and casts the following command argument, a Redis string object, to a Bolt client structure without checking its origin; the result-set code then dereferences pointers read from that object. The argument is parsed even when the Bolt endpoint is disabled, so default configurations are affected.
Published: 2026-10-09
Score: 7.7 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade FalkorDB to version 4.20.0 or later. Bolt protocol support, including the code affected by this issue, was removed in 4.20.0.


Vendor Workaround

Use Redis ACLs to restrict the GRAPH.QUERY command to trusted users, and do not expose the instance to untrusted networks.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
Description A type confusion vulnerability in the _read_flags function (src/commands/cmd_dispatcher.c) in FalkorDB before 4.20.0 allows a remote authenticated attacker who can run GRAPH.QUERY to cause a denial of service and possibly disclose or corrupt memory. The function accepts a --bolt argument from any client and casts the following command argument, a Redis string object, to a Bolt client structure without checking its origin; the result-set code then dereferences pointers read from that object. The argument is parsed even when the Bolt endpoint is disabled, so default configurations are affected.
Title Type confusion in FalkorDB GRAPH.QUERY via the --bolt argument
First Time appeared Falkordb
Falkordb falkordb
Weaknesses CWE-843
CPEs cpe:2.3:a:falkordb:falkordb:*:*:*:*:*:*:*:*
Vendors & Products Falkordb
Falkordb falkordb
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Falkordb Falkordb
cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-09T05:08:14.899Z

Reserved: 2026-10-09T04:55:02.081Z

Link: CVE-2026-107911

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')