rootpwn

high · CVSS v3 7.5

CVE-2026-88406

FalkorDB Redis module versions 4.20.1 through 4.20.4 contain a stack overflow in the _ValidateUnion_Clauses function that can be triggered b

Overview

FalkorDB Redis module versions 4.20.1 through 4.20.4 contain a stack overflow in the _ValidateUnion_Clauses function that can be triggered by crafted input. This flaw allows an attacker to cause a denial‑of‑service (DoS) by crashing the module. The vulnerability is limited to the FalkorDB module and does not expose data or allow remote code execution.

Description

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

Impact

The primary impact is a loss of availability for services that rely on FalkorDB, potentially disrupting application functionality and user access. Availability is compromised, while confidentiality and integrity remain unaffected. Administrators and end users of affected systems are directly impacted.

Remediation

Upgrade to FalkorDB 4.20.5 or later, which contains the fix for the stack overflow. If an upgrade is not immediately possible, disable the FalkorDB module or restrict its exposure to trusted networks, and monitor for abnormal crashes or memory usage. Apply any vendor‑issued hotfixes as soon as they become available.

Risk context

The CVSS v3 score of 7.5 classifies this as a high‑severity vulnerability, indicating a significant risk of service disruption. While no EPSS data is available, the potential for DoS warrants prompt attention from defenders.

Affected products

  • FalkorDB 4.20.1
  • FalkorDB 4.20.2
  • FalkorDB 4.20.3
  • FalkorDB 4.20.4

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
EPSS

DoS StackOverflow RedisModule FalkorDB HighSeverity Availability Patch

← All CVEs