VYPR
Vendor

FalkorDB

Products
3
CVEs
9
Across products
9
Status
Private

Products

3

Recent CVEs

9
  • CVE-2026-88409HigSep 21, 2026
    risk 0.57cvss 8.8epss 0.00

    FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-6057CriApr 10, 2026
    risk 0.57cvss 9.8epss 0.01

    FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.

  • CVE-2026-88407HigSep 21, 2026
    risk 0.49cvss 7.5epss 0.00

    An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-88406HigSep 21, 2026
    risk 0.49cvss 7.5epss 0.00

    FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-88410HigSep 21, 2026
    risk 0.46cvss 7.1epss 0.00

    The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the application.

  • CVE-2026-10130HigJul 18, 2026
    risk 0.46cvss 8.2epss 0.01

    QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. The signup route unconditionally creates and links a new token…

  • CVE-2026-88411HigSep 21, 2026
    risk 0.42cvss 7.5epss 0.00

    Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application.

  • CVE-2026-88408MedSep 21, 2026
    risk 0.42cvss 6.5epss 0.00

    FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-88412MedSep 21, 2026
    risk 0.34cvss 5.3epss 0.00

    An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.