Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade FalkorDB to version 4.18.1 or later.
Vendor Workaround
Require authentication on the Redis/FalkorDB instance (requirepass or ACLs), restrict or rename the REPLICAOF/SLAVEOF commands so untrusted clients cannot use them, and do not expose the instance to untrusted networks.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.1 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or execute arbitrary code in the redis-server process by supplying a crafted RDB stream whose deleted-nodes buffer length is not a multiple of sizeof(NodeID). The length check relies on ASSERT(), which is compiled out in release builds, so the function continues after freeing the buffer, reading it and freeing it a second time. | |
| Title | Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code execution via crafted RDB | |
| First Time appeared |
Falkordb
Falkordb falkordb |
|
| Weaknesses | CWE-415 CWE-416 |
|
| CPEs | cpe:2.3:a:falkordb:falkordb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Falkordb
Falkordb falkordb |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: securin
Published:
Updated: 2026-10-09T04:04:28.078Z
Reserved: 2026-04-07T17:26:12.107Z
Link: CVE-2026-5759
No data.
Status : Deferred
Published: 2026-10-09T05:16:44.920
Modified: 2026-10-09T05:16:45.043
Link: CVE-2026-5759
No data.
OpenCVE Enrichment
Updated: 2026-10-09T07:30:17Z
