← Back to search

CVE-2026-88407

7.5 HIGHpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw in FalkorDB (Redis module) allows out-of-bounds read leading to Denial of Service via crafted input, posing a significant risk.
Exploitability
Exploitation requires crafting specific input and access to the affected version; moderate difficulty.
Blast radius
If exploited, it could disrupt services for users relying on FalkorDB v4.20.1 to v4.20.4, impacting availability.
Prioritized remediation
Update to FalkorDB v4.21 or later versions immediately to mitigate the risk.
dosredisdb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.