Sceawere

Vulnerability Detail

CVE-2026-5759UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FalkorDB RDB Double Free Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
5h ago
Vendor
FalkorDB
Product
FalkorDB
Attack Type
CWE-415 Double Free
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.1 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or execute arbitrary code in the redis-server process by supplying a crafted RDB stream whose deleted-nodes buffer length is not a multiple of sizeof(NodeID). The length check relies on ASSERT(), which is compiled out in release builds, so the function continues after freeing the buffer, reading it and freeing it a second time.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-09T05:16:44.920Z",
  "pubdate": "2026-10-09T05:16:44.920Z",
  "executiveSummary": "A critical memory management vulnerability exists in the RdbLoadDeletedNodes function within the RDB graph decoders of FalkorDB prior to version 4.18.1.\nThe flaw manifests as a double-free and use-after-free condition triggered by improperly validated RDB streams.\nAn unauthenticated remote attacker capable of issuing Redis replication commands can leverage this vulnerability to trigger memory corruption within the redis-server process.\nSuccessful exploitation may lead to a denial of service (DoS) via application crash or potentially remote code execution (RCE) depending on heap layout manipulation.\nThe risk is exacerbated by the reliance on development-only assertions for critical safety checks, which are absent in production release builds.\nSecurity teams should prioritize upgrading to version 4.18.1 or later and restricting network access to the Redis replication interface.",
  "technicalDetails": "The vulnerability resides in the RdbLoadDeletedNodes function located in src/serializers/decoders/*/decode_graph_entities.c. The root cause is a deficiency in input validation concerning the length of the deleted-nodes buffer in the RDB stream.\nSpecifically, the decoder expects the length of the deleted-nodes buffer to be an exact multiple of sizeof(NodeID). Validation is performed using the ASSERT() macro, which evaluates input integrity during debug execution but is stripped during release build compilation.\nWhen a crafted RDB payload is supplied where the length is not a multiple of sizeof(NodeID), the runtime execution flow continues past the sanity check in production builds. The function then proceeds to free the buffer, but because the logic flow is flawed, it subsequently performs a use-after-free and a secondary free operation on the same memory pointer.\nThe attack flow begins with an attacker targeting a redis-server instance, potentially one lacking authentication/password protection. The attacker initiates a malicious replication process, forcing the server to process a crafted RDB stream.\nUpon encountering the malformed buffer length, the decoder executes the initial free on the memory block. Because the length validation logic is bypassed, the code path does not exit, leading the application to perform operations on the dangling pointer (use-after-free). This allows for heap grooming or corruption of sensitive application state.\nThe process then hits the second free operation on the already deallocated address, triggering an invalid free error, which can cause the process to abort. In an exploit scenario, an attacker could manipulate the heap layout to gain control over instruction pointers or data structures, potentially achieving arbitrary code execution within the context of the redis-server process.\nThis vulnerability affects FalkorDB versions prior to 4.18.1 and necessitates immediate attention due to the ease of reachability through the Redis replication protocol if the service is exposed to an untrusted network."
}
CVE-2026-5759: FalkorDB RDB Double Free Vulnerability (CRITICAL Severity, CVSS: 9.8) | Sceawere