NVD disclosure day

Published threat advisories for October 9, 2026

CVE advisoryCRITICAL

CVE-2026-107910

FalkorDB Bolt Endpoint Authentication Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An improper authentication vulnerability in FalkorDB's Bolt endpoint allows unauthenticated remote attackers to execute graph queries by exploiting flawed logic in the authentication function. If the Bolt endpoint is enabled, certain operational errors can cause the system to incorrectly authenticate attackers, grantin

CVE advisoryCRITICAL

CVE-2026-107908

FalkorDB Bolt Protocol Denial of Service and Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap-based out-of-bounds write in FalkorDB's Bolt protocol handler may allow unauthenticated remote attackers to cause a denial of service or execute code by sending a crafted message, but only affects deployments where the Bolt endpoint is enabled.

CVE advisoryCRITICAL

CVE-2026-5759

FalkorDB RDB Decoder Double Free and Use-After-Free Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

FalkorDB's RDB decoders contain a double free and use-after-free vulnerability in the `RdbLoadDeletedNodes` function. An attacker could exploit this by sending a crafted RDB stream to an unprotected instance, potentially leading to denial of service or arbitrary code execution. The primary concern is confirming FalkorD