CVE-2026-7826: Heap out-of-bounds read in FalkorDB BufferSerializerIOv2_ReadBuffer via crafted RDB

Published Oct 9, 2026
·
Updated

A heap-based out-of-bounds read in the BufferSerializerIOv2ReadBuffer function (src/serializers/serializerio.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or disclose heap memory by supplying a crafted RDB stream whose sub-buffer length field exceeds the remaining buffer size. The only bounds check is an ASSERT(), which is compiled out in release builds, so memcpy() reads past the end of the heap allocation.

Affected Software

1 affected component
FalkorDB FalkorDB<4.18.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FalkorDB to a version that resolves this vulnerability.

    Fixed in 4.18.4

Event History

Oct 9, 2026
CVE Published
via MITRE·04:04 AM
Data Sourced
via MITRE·04:04 AM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are most exposed to exploitation?

Instances that permit an attacker to issue Redis replication commands are exposed. The description specifically identifies instances with no password configured as an example of reachable targets.

2

What must an attacker provide to trigger the flaw?

The attacker needs to supply a crafted RDB stream with a sub-buffer length field larger than the remaining buffer size. This causes the release-build memcpy() operation to read beyond the heap allocation.

3

Are production release builds affected by the existing bounds check?

Yes. The only stated bounds check is an ASSERT(), and it is compiled out in release builds, leaving the out-of-bounds read unchecked.

4

What versions need remediation?

FalkorDB versions before 4.18.4 are affected. Updating to 4.18.4 or later addresses the affected version range described in the advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203