Overview
FalkorDB maintainers have shipped a second fix within weeks of their prior RDB-decoder bug, this time for CVE-2026-7826, a heap-based out-of-bounds read rated CVSS 3.1 9.1 (Critical). Like its sibling flaw, it's reachable by any remote party able to send Redis replication traffic to an unauthenticated FalkorDB instance — a reminder that one disclosure in a codebase's deserialization layer is rarely the only one.
FalkorDB is the Redis-module graph database that succeeded RedisGraph and is commonly deployed as the backing store for GraphRAG and knowledge-graph features in AI applications.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-7826 |
| Severity | Critical (CVSS 3.1: 9.1, CVSS 4.0: 8.8) |
| CWE | CWE-125 (Out-of-Bounds Read) |
| Attack Vector | Network |
| Authentication | None Required |
| Affected Component | BufferSerializerIOv2_ReadBuffer — src/serializers/serializer_io.c |
| Affected Versions | FalkorDB before 4.18.4 |
| Fixed Version | 4.18.4 |
How It Works
BufferSerializerIOv2_ReadBuffer deserializes sub-buffers out of an incoming RDB byte stream during replication. The only safeguard against a malicious length field was — once again — an ASSERT() call, compiled out in release builds. An attacker can send a crafted RDB stream in which a sub-buffer's declared length field exceeds the remaining space in the actual buffer. Because the runtime check is absent, the function proceeds to copy past the end of the allocated buffer, reading adjacent heap memory.
Depending on what's adjacent in the heap, this can crash the process (denial of service) or leak heap contents — including, potentially, fragments of other data resident in the same redis-server process — back to the attacker through subsequent protocol responses or error behavior.
A related flaw, CVE-2026-7827 (a stack-based overflow in _RdbLoadEntity), was identified and fixed in the same release.
Impact Assessment
Who Is At Risk
- FalkorDB deployments running versions earlier than 4.18.4
- Instances without Redis AUTH configured, or reachable on the replication port from untrusted network segments
- Any environment where FalkorDB has not yet been patched following the CVE-2026-5759 advisory from the same month — if you missed that one, assume you've missed this one too
Potential Consequences
- Denial of Service — A malformed sub-buffer length field can crash the hosting
redis-serverprocess. - Heap Memory Disclosure — Out-of-bounds reads can leak adjacent heap data, which may include fragments of other keys, session state, or application data resident in the same process.
Mitigation
Immediate Actions
- Upgrade to FalkorDB 4.18.4 or later — the fix (tracked as Issue #1975, shipped via PR #1972) adds runtime validation of the type byte, declared length, and copy size before any
memcpy, aborting safely instead of reading out of bounds. - Enable Redis AUTH on every instance; do not depend on network isolation as the only control.
- Firewall the replication port to known, trusted primary/replica pairs only.
Detection Opportunities
- Watch for
redis-servercrashes or anomalous memory-access patterns coinciding with inbound RDB/replication traffic from unexpected sources. - If upgrading isn't immediately possible, consider temporarily disabling replication from untrusted sources until patched.
Defence-in-Depth
- Treat FalkorDB (and any Redis-module-based data store) with the same patch cadence discipline as internet-facing edge services — two critical deserialization bugs in one release cycle suggests more may follow in this code path.
Disclosure Timeline
The fix for this issue was merged on May 7, 2026 and released the same day as FalkorDB 4.18.4. No GitHub Security Advisory (GHSA) has been published for this CVE as of this writing, and no public proof-of-concept exploit is currently known.