A type confusion vulnerability in the _read_flags function (src/commands/cmd_dispatcher.c) in FalkorDB before 4.20.0 allows a remote authenticated attacker who can run GRAPH.QUERY to cause a denial of service and possibly disclose or corrupt memory. The function accepts a --bolt argument from any client and casts the following command argument, a Redis string object, to a Bolt client structure without checking its origin; the result-set code then dereferences pointers read from that object. The argument is parsed even when the Bolt endpoint is disabled, so default configurations are affected.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
FalkorDB versions before 4.20.0 contain a type confusion vulnerability in the _read_flags function that allows authenticated attackers to trigger denial of service conditions and potentially read or corrupt sensitive memory. The vulnerability exists because the function unsafely casts Redis string objects to Bolt client structures without validating their origin, then dereferences pointers from this untrusted data. Organizations running FalkorDB as part of their graph database infrastructure face immediate risk if they allow multiple clients or federated query access, as any authenticated user can exploit this by crafting malicious --bolt arguments to GRAPH.QUERY commands.
While this CVE lacks direct MITRE ATT&CK technique mappings, Casky's 754 mapped security skills enable detection of the underlying attack patterns through Claude's extended reasoning capabilities. Practitioners using Casky would identify this vulnerability through detection of abnormal memory access patterns, unexpected process crashes tied to graph query execution, and anomalous pointer dereferences in command dispatcher logs. The platform's skill set would flag unsafe type casting behaviors and unchecked object transformations as indicators of CWE-843 violations. Security teams would see findings highlighting the absence of input validation on client-supplied structures and recommendations to implement strict type checking and origin verification before any cast operations in the command parsing pipeline.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-107911. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation