CVE-2026-7826: Heap out-of-bounds read in FalkorDB BufferSerializerIOv2_ReadBuffer via crafted RDB
A heap-based out-of-bounds read in the BufferSerializerIOv2ReadBuffer function (src/serializers/serializerio.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or disclose heap memory by supplying a crafted RDB stream whose sub-buffer length field exceeds the remaining buffer size. The only bounds check is an ASSERT(), which is compiled out in release builds, so memcpy() reads past the end of the heap allocation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FalkorDBto a version that resolves this vulnerability.Fixed in 4.18.4
Event History
Frequently Asked Questions
Which deployments are most exposed to exploitation?
Instances that permit an attacker to issue Redis replication commands are exposed. The description specifically identifies instances with no password configured as an example of reachable targets.
What must an attacker provide to trigger the flaw?
The attacker needs to supply a crafted RDB stream with a sub-buffer length field larger than the remaining buffer size. This causes the release-build memcpy() operation to read beyond the heap allocation.
Are production release builds affected by the existing bounds check?
Yes. The only stated bounds check is an ASSERT(), and it is compiled out in release builds, leaving the out-of-bounds read unchecked.
What versions need remediation?
FalkorDB versions before 4.18.4 are affected. Updating to 4.18.4 or later addresses the affected version range described in the advisory.