CVE-2026-107908: Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET message
A heap-based out-of-bounds write in the BoltReadHandler function (src/bolt/boltapi.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to cause a denial of service and possibly execute arbitrary code by sending a Bolt RESET message with an attacker-chosen chunk size to the Bolt port. The handler checks the size only with ASSERT(), which is compiled out in release builds, then computes a destination pointer from the wire-supplied 16-bit size and moves buffered data up to about 64 KiB backwards past the start of the read buffer. Only deployments that enable the Bolt endpoint (BOLTPORT, disabled by default) are affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FalkorDBto a version that resolves this vulnerability.Fixed in 4.20.0 - Configuration
Disable the Bolt endpoint if it is not required; it is disabled by default.
FalkorDB Bolt endpoint BOLT_PORT = disabled
Event History
Frequently Asked Questions
Which deployments are exposed?
Only FalkorDB deployments with the Bolt endpoint enabled through BOLT_PORT are affected. The Bolt endpoint is disabled by default, so deployments that have not enabled it are not exposed through this issue.
What does an attacker need to exploit this vulnerability?
An attacker needs network access to the enabled Bolt port and can exploit the issue without authentication, privileges, or user interaction. Exploitation involves sending a Bolt RESET message containing an attacker-chosen chunk size.
What is the immediate mitigation if upgrading is not possible?
Disable the Bolt endpoint by removing or disabling BOLT_PORT. If the endpoint must remain enabled, restrict network access to the Bolt port to trusted sources until FalkorDB is updated.
How can I determine whether my instance is affected?
Check whether the instance runs a FalkorDB version before 4.20.0 and whether BOLT_PORT is enabled. Affected configurations expose the Bolt endpoint; the vulnerable code is in BoltReadHandler in src/bolt/bolt_api.c.