External risk intelligence

FalkorDB Bolt Protocol Denial of Service and Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-107908

The vulnerability affects the Bolt protocol handler in FalkorDB. While the Bolt port can be network-reachable, it is disabled by default in typical deployments and is generally intended for internal database communication rather than direct public internet exposure. Therefore, while it is plausibly reachable in some specific configurations, it is not commonly exposed as a public-facing service.

Out-of-bounds Write

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in FalkorDB's Bolt protocol handler. The issue could allow unauthenticated attackers to disrupt services or potentially execute code by sending a specially crafted message. This threat is relevant only to deployments that have explicitly enabled the Bolt endpoint, which is disabled by default.

  • Flaw in message handling permits remote disruption.
  • Matters if Bolt port is enabled for external access.
  • Confirm relevance; exposure is unlikely by default.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can send a specially crafted message over the network to FalkorDB's Bolt port, if enabled. This message manipulates the size of data to be written, causing a buffer overflow within the BoltReadHandler function. This can lead to denial of service and potentially arbitrary code execution.

  • Network access to enabled Bolt port.
  • Sending a Bolt RESET with attacker-chosen size.
  • Denial of service or arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A heap-based out-of-bounds write could affect FalkorDB deployments that enable the Bolt endpoint. When supported, an attacker could trigger this by sending a specially crafted Bolt RESET message, potentially leading to denial of service or arbitrary code execution by overwriting memory.

  • System integrity and availability.
  • Via network through Bolt port.
  • Denial of service or code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for FalkorDB deployments, particularly those enabling the Bolt endpoint, should lead the initial response. The first practical move is to identify all instances of the affected technology, confirm if the Bolt port is enabled and reachable, assess business criticality, and then assign an owner to plan remediation based on risk.

  • Application or platform owners.
  • Verify Bolt endpoint enablement and reachability.
  • Plan maintenance for targeted remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is FalkorDB and why does it use the Bolt protocol?

FalkorDB is a high-performance graph database designed for complex data relationships. The Bolt protocol is a binary communication language used by the database to handle efficient data exchange between clients and the server. In this software, specific handlers manage these incoming messages to process commands or database resets effectively.

How would you describe the CWE-787 weakness in CVE-2026-107908?

This is a heap-based out-of-bounds write. Imagine a piece of software that reserves a specific area of memory to process incoming data, but fails to properly check if the data actually fits. An attacker can supply a malicious size value, tricking the program into writing data outside of its assigned memory space. This can overwrite critical system information, potentially leading to a system crash or allowing the execution of unauthorized commands.

What does an attacker need to trigger this vulnerability?

An attacker must be able to reach the Bolt port of a vulnerable FalkorDB instance over the network. They trigger the issue by sending a specially crafted 'RESET' message containing a manipulated chunk size. If the Bolt port is disabled, or if the database is running a version where this logic is absent or patched, the trigger will not function.

Do I need to worry about this if my FalkorDB is not public?

According to Halo Surface Signal, this vulnerability is most relevant when the Bolt port is explicitly enabled and network-reachable. While the port is disabled by default, if your configuration enables it for any network traffic, you should assess the risk. If your database exists only in an isolated internal environment with no exposure to untrusted users, your immediate risk is lower, but verification is still advised.

What is the recommended first step to respond to this?

First, conduct an inventory of all FalkorDB deployments to identify where the software is running. Next, check your configuration files to see if the Bolt port is enabled. If it is active, prioritize assessing whether those instances are reachable over your network. Once you have identified these specific systems, you can move toward scheduling maintenance to update the software.

References