rootpwn

high · CVSS v3 7.5

CVE-2026-88407

FalkorDB, a Redis module, has an out-of-bounds read in the node_token_count/relation_token_count component. Versions 4.20.1 to 4.20.4 are af

Overview

FalkorDB, a Redis module, has an out-of-bounds read in the node_token_count/relation_token_count component. Versions 4.20.1 to 4.20.4 are affected. The flaw can lead to a denial of service when a crafted input is processed.

Description

An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Impact

The vulnerability does not compromise confidentiality or integrity but disrupts availability by causing a crash or slowdown. It can affect any environment running FalkorDB within Redis, including production and staging systems. Operators should be aware that an attacker could trigger repeated crashes, impacting service uptime.

Remediation

Upgrade FalkorDB to v4.20.5 or later. If upgrade not possible, temporarily disable the node_token_count/relation_token_count feature or unload the module until patch. Monitor Redis logs for abnormal memory reads and restart services if crashes occur.

Risk context

High severity (CVSS 7.5) indicates a significant risk of service disruption. While no EPSS data is available, the lack of mitigation in current releases warrants prompt action.

Affected products

  • FalkorDB
  • Redis module

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
EPSS

DoS Redis module out-of-bounds availability FalkorDB

← All CVEs