Sceawere
Vulnerability Detail
CVE-2026-107911UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FalkorDB Type Confusion Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 4h ago
- Vendor
- FalkorDB
- Product
- FalkorDB
- Attack Type
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
A type confusion vulnerability in the _read_flags function (src/commands/cmd_dispatcher.c) in FalkorDB before 4.20.0 allows a remote authenticated attacker who can run GRAPH.QUERY to cause a denial of service and possibly disclose or corrupt memory. The function accepts a --bolt argument from any client and casts the following command argument, a Redis string object, to a Bolt client structure without checking its origin; the result-set code then dereferences pointers read from that object. The argument is parsed even when the Bolt endpoint is disabled, so default configurations are affected.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-09T06:17:12.620Z",
"pubdate": "2026-10-09T06:17:12.620Z",
"executiveSummary": "FalkorDB versions prior to 4.20.0 contain a critical type confusion vulnerability within the _read_flags function located in src/commands/cmd_dispatcher.c.\nThe vulnerability originates from improper input validation where a user-supplied Redis string object is unsafely cast into a Bolt client structure without origin verification.\nThis flaw can be exploited by a remote authenticated attacker executing the GRAPH.QUERY command, even when the Bolt endpoint is explicitly disabled in the system configuration.\nSuccessful exploitation allows an attacker to trigger a denial of service through application instability or potentially achieve unauthorized memory disclosure and data corruption.\nThe vulnerability presents a significant security risk, as it permits an attacker to manipulate internal memory structures by providing malicious inputs that the application misinterprets as valid control structures.\nSecurity teams should treat this as a high-priority issue due to the potential for memory corruption and the ability to influence sensitive application-level memory operations.",
"technicalDetails": "The vulnerability resides in the _read_flags function within src/commands/cmd_dispatcher.c. The root cause is an inadequate type-checking mechanism when processing command arguments. Specifically, the function receives a --bolt argument provided by a client and performs a direct cast of the subsequent Redis string object into a Bolt client structure. This operation is performed without validating that the source object actually conforms to the expected structure type.\nThe attack flow begins when an authenticated attacker invokes the GRAPH.QUERY command. Even when the Bolt protocol interface is disabled via configuration, the _read_flags function continues to process the arguments. By injecting a crafted Redis string object, an attacker forces the dispatcher to treat this object as a pointer to a legitimate Bolt client object.\nWhen the internal result-set logic executes, it proceeds to dereference pointers contained within the now-misinterpreted object. Because the attacker controls the contents of the Redis string object, they effectively control the memory addresses that the application attempts to dereference. This leads to undefined behavior during pointer arithmetic and dereferencing operations.\nThe exploitation method relies on the memory layout of the attacker-controlled Redis object. By carefully structuring the payload, an attacker can influence the execution flow. If the dereferenced pointers refer to invalid or unauthorized memory locations, the process will trigger a segmentation fault or a kernel-level panic, resulting in a denial of service.\nFurthermore, if the attacker can influence the memory addresses accessed during these operations, they may be able to read sensitive data residing in the heap, leading to memory disclosure. In more advanced scenarios, the ability to control dereferenced addresses may allow for primitive arbitrary read or write operations, facilitating data corruption or potentially further system compromise.\nBecause the logic fails to check whether the Bolt functionality is enabled before processing the argument, the attack surface remains exposed in default configurations, meaning the vulnerability is not restricted to systems explicitly enabling Bolt connectivity. The lack of validation regarding the origin and type of the input data is the primary failure point in the security architecture of the command dispatcher."
}