high · CVSS v3 7.1
CVE-2026-88410
The FalkorDB Redis module (v4.20.1‑v4.20.4) contains a bug where the graph.UDF command is not registered as a write command, causing unexpec
Overview
The FalkorDB Redis module (v4.20.1‑v4.20.4) contains a bug where the graph.UDF command is not registered as a write command, causing unexpected application behavior. This flaw can lead to data integrity issues or denial of service within systems that rely on FalkorDB for graph operations. Defenders should be aware that any deployment of these specific module versions is potentially impacted.
Description
The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the application.
Impact
The misregistration can compromise the integrity of graph data, potentially allowing unintended modifications or corrupting data structures. Availability may also be affected if the module enters an unstable state, leading to service interruptions. Confidentiality is not directly impacted, but the integrity and availability of the application are at risk for administrators, developers, and end‑users of FalkorDB.
Remediation
Apply the latest FalkorDB release (v4.20.5 or newer) where graph.UDF is correctly registered as a write command. If an upgrade is not immediately possible, restrict or disable the graph.UDF command via ACLs or configuration, and monitor Redis logs for anomalous command usage. Verify that all instances are updated and test for normal operation after remediation.
Risk context
The vulnerability is rated high with a CVSS v3 score of 7.1. While no EPSS data is available, the severity indicates a moderate to high urgency for affected deployments to apply the patch or mitigation promptly.
Affected products
- FalkorDB v4.20.1
- FalkorDB v4.20.2
- FalkorDB v4.20.3
- FalkorDB v4.20.4
- Redis module FalkorDB
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 7.1
- CVSS v4
- —
- EPSS
- —