Sceawere
Vulnerability Detail
CVE-2026-7827UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FalkorDB Stack-Based Buffer Overflow
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 5h ago
- Vendor
- FalkorDB
- Product
- FalkorDB
- Attack Type
- CWE-121 Stack-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
A stack-based buffer overflow in the _RdbLoadEntity function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service and possibly execute arbitrary code by supplying a crafted RDB stream with an attacker-controlled entity property count. The count sizes two variable-length arrays on the thread stack with no upper bound, and the decoder then fills them with attacker-supplied values.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-09T05:16:45.327Z",
"pubdate": "2026-10-09T05:16:45.327Z",
"executiveSummary": "A critical stack-based buffer overflow vulnerability exists in FalkorDB versions prior to 4.18.4, specifically within the RDB graph entity decoding logic.\nThe vulnerability resides in the _RdbLoadEntity function located in src/serializers/decoders/*/decode_graph_entities.c, which fails to perform bounds checking on entity property counts during RDB stream processing.\nAn unauthenticated remote attacker capable of issuing Redis replication commands can exploit this flaw by providing a maliciously crafted RDB stream containing an attacker-controlled property count.\nSuccessful exploitation allows for memory corruption on the thread stack, leading to a Denial of Service (DoS) or the potential for arbitrary code execution with the privileges of the FalkorDB process.\nThe risk is elevated in environments where Redis instances are exposed without authentication, as the RDB loading process can be triggered remotely without prior authorization.\nRemediation requires updating FalkorDB to version 4.18.4 or later to implement proper input validation and size constraints on stack-allocated structures.",
"technicalDetails": "The root cause of this vulnerability is an improper implementation of memory allocation for variable-length arrays (VLAs) within the _RdbLoadEntity function. The function processes RDB data streams for graph entities and uses the property count value, derived directly from the input stream, to allocate storage for properties on the thread stack.\nBecause the input property count is not subjected to an upper-bound check before the stack allocation, an attacker can specify an excessively large integer. This results in a stack-based buffer overflow when the subsequent decoding logic attempts to write attacker-supplied property data into the insufficiently sized or incorrectly calculated stack memory space.\nThe exploitation flow begins when an attacker initiates a Redis replication handshake or provides a crafted RDB payload to the FalkorDB instance. In instances where no password is required, the replication mechanism allows the attacker to inject the payload directly into the decoders. As the _RdbLoadEntity function executes, it reads the untrusted property count from the RDB stream and allocates memory on the thread stack to accommodate the incoming entities.\nBy manipulating the RDB stream to provide a large entity property count, the attacker forces the decoder to perform out-of-bounds writes to the stack. This memory corruption can overwrite critical return addresses or function pointers stored on the stack frame. If the attacker crafts the payload to overwrite the instruction pointer (IP) or other control flow structures, they can redirect execution to an attacker-controlled code segment, such as a ROP chain or shellcode injected within the payload itself.\nThe vulnerability affects all versions of FalkorDB prior to 4.18.4. Because the vulnerable component is part of the core RDB graph entity decoder, any instance capable of ingesting RDB files or replication commands is susceptible to this attack vector. The lack of stack canaries or other modern exploit mitigation techniques in the vulnerable code path may further facilitate the successful execution of arbitrary code, resulting in total system compromise if the service runs with high privileges."
}