No advisories yet.
Solution
Upgrade FalkorDB to version 4.20.0 or later. Bolt protocol support, including the code affected by this issue, was removed in 4.20.0.
Workaround
Use Redis ACLs to restrict the GRAPH.QUERY command to trusted users, and do not expose the instance to untrusted networks.
Fri, 09 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Oct 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A type confusion vulnerability in the _read_flags function (src/commands/cmd_dispatcher.c) in FalkorDB before 4.20.0 allows a remote authenticated attacker who can run GRAPH.QUERY to cause a denial of service and possibly disclose or corrupt memory. The function accepts a --bolt argument from any client and casts the following command argument, a Redis string object, to a Bolt client structure without checking its origin; the result-set code then dereferences pointers read from that object. The argument is parsed even when the Bolt endpoint is disabled, so default configurations are affected. | |
| Title | Type confusion in FalkorDB GRAPH.QUERY via the --bolt argument | |
| First Time appeared |
Falkordb
Falkordb falkordb |
|
| Weaknesses | CWE-843 | |
| CPEs | cpe:2.3:a:falkordb:falkordb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Falkordb
Falkordb falkordb |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: securin
Published:
Updated: 2026-10-09T16:47:39.583Z
Reserved: 2026-10-09T04:55:02.081Z
Link: CVE-2026-107911
Updated: 2026-10-09T16:16:18.892Z
Status : Deferred
Published: 2026-10-09T06:17:12.620
Modified: 2026-10-09T17:16:46.130
Link: CVE-2026-107911
No data.
OpenCVE Enrichment
Updated: 2026-10-09T06:30:17Z