{"id":"CVE-2026-88412","published":"2026-09-21T21:17:15.513","lastModified":"2026-09-21T21:17:15.513","description":"An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://github.com/FalkorDB/FalkorDB/issues/2326","tags":[]}],"exploitRefs":[{"url":"https://github.com/FalkorDB/FalkorDB/issues/2326","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw involves an integer overflow in FalkorDB's Redis module v4.20.1, allowing attackers to cause a Denial of Service via crafted input, which could disrupt service availability.","exploitability":"Exploitation requires crafting specific input, making it moderately difficult but feasible for advanced attackers.","blast_radius":"If exploited, this flaw could significantly impact service availability, potentially leading to downtime or performance degradation in affected systems.","remediation":"Update FalkorDB Redis module to a patched version immediately to mitigate the risk of DoS attacks.","tags":["dos","redis","db"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:28:58.827Z"}}