
🚨Critical - FalkorDB Memory Corruption Issues (CVE-2026-5759 / CVE-2026-107908) FalkorDB has two critical memory corruption issues caused by ASSERT() checks that are compiled out in release builds. A crafted RDB stream triggers double free + use-after-free in RdbLoadDeletedNodes (CVE-2026-5759), and a Bolt RESET message with attacker-chosen chunk size causes heap OOB write in BoltReadHandler (CVE-2026-107908). Both allow remote unauthenticated DoS and potentially RCE. Deployments with Bolt disabled (BOLT_PORT unset, default) are not affected by the Bolt issue. 👉Affected: FalkorDB < 4.20.0 | Upgrade to 4.20.0
