CVE-2026-88407: High severity FalkorDB FalkorDB (Redis module) vulnerability
Published Sep 21, 2026
·Updated
An out-of-bounds read in the nodetokencount/relationtokencount component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Affected Software
1 affected component
FalkorDB FalkorDB (Redis module)>=4.20.1<=4.20.4
Event History
Sep 21, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·09:17 PM
DescriptionSeverity
Frequently Asked Questions
1
Which deployments should be prioritized for remediation?
FalkorDB Redis module versions 4.20.1 through 4.20.4 are identified as affected. Deployments running one of those versions should be prioritized.
2
Does an attacker need authentication or user interaction to trigger the issue?
No. The listed vector indicates network access is sufficient, with no privileges or user interaction required.