{"id":"CVE-2026-88411","published":"2026-09-21T21:17:15.380","lastModified":"2026-09-21T21:17:15.380","description":"Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://github.com/FalkorDB/FalkorDB/commit/17cb1f8f0","tags":[]},{"url":"https://github.com/FalkorDB/FalkorDB/pull/2247","tags":[]}],"exploitRefs":[{"url":"https://github.com/FalkorDB/FalkorDB/commit/17cb1f8f0","tags":[]},{"url":"https://github.com/FalkorDB/FalkorDB/pull/2247","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw involves improper error handling in FalkorDB v4.20.1's GRAPH.EFFECT component, leading to a Denial of Service (DoS). This matters because attackers can exploit it to disrupt service without needing specific privileges.","exploitability":"Exploitation is relatively easy with public exploits available; requires access to the affected Redis module version.","blast_radius":"If exploited, this could significantly impact availability, causing widespread service disruptions for users of FalkorDB v4.20.1.","remediation":"Update to a patched version of FalkorDB or apply vendor-provided patches immediately.","tags":["dos","redis","db"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:14:37.218Z"}}