CVE-2026-88408: Medium severity FalkorDB (Redis module) vulnerability
Published Sep 21, 2026
·Updated
FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the GetGroup() function (/ops/opaggregate.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Affected Software
1 affected component
FalkorDB (Redis module)>=4.20.1<=4.20.4
Event History
Sep 21, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·09:17 PM
DescriptionSeverity
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is remotely reachable over the network and requires low-level privileges. No user interaction is required.
2
Which versions are known to be affected?
FalkorDB Redis module versions 4.20.1 through 4.20.4 are identified as affected.
3
What is the expected impact of successful exploitation?
A crafted input can trigger a stack overflow in _GetGroup() in /ops/op_aggregate.c, causing a denial of service. The provided severity data indicates availability impact only, with no stated confidentiality or integrity impact.