CVE-2026-107908: Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET message

Published Oct 9, 2026
·
Updated

A heap-based out-of-bounds write in the BoltReadHandler function (src/bolt/boltapi.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to cause a denial of service and possibly execute arbitrary code by sending a Bolt RESET message with an attacker-chosen chunk size to the Bolt port. The handler checks the size only with ASSERT(), which is compiled out in release builds, then computes a destination pointer from the wire-supplied 16-bit size and moves buffered data up to about 64 KiB backwards past the start of the read buffer. Only deployments that enable the Bolt endpoint (BOLTPORT, disabled by default) are affected.

Affected Software

1 affected component
FalkorDB FalkorDB<4.20.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FalkorDB to a version that resolves this vulnerability.

    Fixed in 4.20.0
  2. Configuration

    Disable the Bolt endpoint if it is not required; it is disabled by default.

    FalkorDB Bolt endpoint BOLT_PORT = disabled

Event History

Oct 9, 2026
CVE Published
via MITRE·05:08 AM
Data Sourced
via MITRE·05:08 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Event
via NVD·08:12 PM

Frequently Asked Questions

1

Which deployments are exposed?

Only FalkorDB deployments with the Bolt endpoint enabled through BOLT_PORT are affected. The Bolt endpoint is disabled by default, so deployments that have not enabled it are not exposed through this issue.

2

What does an attacker need to exploit this vulnerability?

An attacker needs network access to the enabled Bolt port and can exploit the issue without authentication, privileges, or user interaction. Exploitation involves sending a Bolt RESET message containing an attacker-chosen chunk size.

3

What is the immediate mitigation if upgrading is not possible?

Disable the Bolt endpoint by removing or disabling BOLT_PORT. If the endpoint must remain enabled, restrict network access to the Bolt port to trusted sources until FalkorDB is updated.

4

How can I determine whether my instance is affected?

Check whether the instance runs a FalkorDB version before 4.20.0 and whether BOLT_PORT is enabled. Affected configurations expose the Bolt endpoint; the vulnerable code is in BoltReadHandler in src/bolt/bolt_api.c.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203