PT-2025-17214 · Unknown+1 · Dragonflydb+1

Ankki-Zsyang

·

Published

2025-04-17

·

Updated

2025-04-19

·

CVE-2025-26268

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions DragonflyDB Dragonfly versions prior to 1.27.0
Description The issue allows authenticated users to cause a denial of service, resulting in a daemon crash, by sending a crafted Redis command. The problem stems from the lack of validation of the scan cursor's validity.
Recommendations For versions prior to 1.27.0, update to version 1.27.0 or later to resolve the issue. As a temporary workaround, consider restricting access to Redis commands to minimize the risk of exploitation.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2025-26268

Affected Products

Dragonflydb
Redis