CVE-2026-107909 FalkorDB 堆越界写入漏洞
影响远程未授权攻击者可造成拒绝服务并可能破坏堆内存
FalkorDB 4.20.0 之前版本的 Bolt WebSocket 处理逻辑存在堆越界写入漏洞。攻击者向 Bolt 端口发送携带 64 位扩展负载长度的 WebSocket 帧,即可触发越界写。该漏洞 CVSS 评分 9.1,属严重级别。
影响范围
FalkorDB 4.20.0 之前的版本,且仅影响启用了 Bolt 端点(BOLT_PORT,默认关闭)的部署。
漏洞详情
漏洞位于 src/bolt/ws.c 的 ws_read_frame 函数和 src/bolt/buffer.c 的 buffer_apply_mask 函数。ws_read_frame 未对 WebSocket 帧声明的 64 位扩展负载长度做上界校验,而 buffer_apply_mask 中唯一的边界检查是 ASSERT(),在 release 构建中会被编译移除。因此攻击者可用自带的 mask key 对接收缓冲区末尾之外的内存执行 XOR 操作,形成堆越界写入。
利用条件与风险
利用无需认证,但前提是目标部署显式启用了 Bolt 端点;默认配置下 BOLT_PORT 关闭,不受影响。一旦满足条件,可导致服务崩溃甚至堆内存破坏,实战风险高。
修复建议
升级至 FalkorDB 4.20.0 或更高版本。若暂时无法升级,应关闭 Bolt 端点(不设置 BOLT_PORT)并限制该端口的网络访问。
A heap-based out-of-bounds write in the ws_read_frame function (src/bolt/ws.c) and the buffer_apply_mask function (src/bolt/buffer.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to cause a denial of service and possibly corrupt heap memory by sending a WebSocket frame with a 64-bit extended payload length to the Bolt port. The payload length is not bounded, and the only bounds check in buffer_apply_mask is an ASSERT(), which is compiled out in release builds, so the function XORs memory beyond the end of the receive buffer with the attacker-supplied mask key. Only deployments that enable the Bolt endpoint (BOLT_PORT, disabled by default) are affected.