We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-26268



Description

DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.

Reserved 2025-02-07 | Published 2025-04-17 | Updated 2025-04-17 | Assigner mitre


LOW: 3.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Problem types

CWE-392 Missing Report of Error Condition

Product status

Default status
unaffected

Any version before 1.27.0
affected

References

github.com/dragonflydb/dragonfly/issues/4466

github.com/...ommit/d1fac0f912edb323a2bdd6404c518cda21eac243

github.com/dragonflydb/dragonfly/compare/v1.26.4...v1.27.0

cve.org (CVE-2025-26268)

nvd.nist.gov (CVE-2025-26268)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-26268

Support options

Helpdesk Chat, Email, Knowledgebase