CVE-2025-26268

DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dragonflydb:dragonfly:*:*:*:*:*:*:*:*

History

25 Apr 2025, 16:33

Type Values Removed Values Added
CWE NVD-CWE-noinfo
Summary
  • (es) DragonflyDB Dragonfly anterior a la versión 1.27.0 permite a los usuarios autenticados provocar una denegación de servicio (fallo del daemon) mediante un comando Redis manipulado específicamente. No se comprobó la validez del cursor de escaneo.
First Time Dragonflydb dragonfly
Dragonflydb
CPE cpe:2.3:a:dragonflydb:dragonfly:*:*:*:*:*:*:*:*
References () https://github.com/dragonflydb/dragonfly/commit/d1fac0f912edb323a2bdd6404c518cda21eac243 - () https://github.com/dragonflydb/dragonfly/commit/d1fac0f912edb323a2bdd6404c518cda21eac243 - Patch
References () https://github.com/dragonflydb/dragonfly/compare/v1.26.4...v1.27.0 - () https://github.com/dragonflydb/dragonfly/compare/v1.26.4...v1.27.0 - Patch, Release Notes
References () https://github.com/dragonflydb/dragonfly/issues/4466 - () https://github.com/dragonflydb/dragonfly/issues/4466 - Exploit, Issue Tracking

17 Apr 2025, 19:16

Type Values Removed Values Added
References () https://github.com/dragonflydb/dragonfly/issues/4466 - () https://github.com/dragonflydb/dragonfly/issues/4466 -

17 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-17 18:15

Updated : 2025-04-25 16:33


NVD link : CVE-2025-26268

Mitre link : CVE-2025-26268

CVE.ORG link : CVE-2025-26268


JSON object : View

Products Affected

dragonflydb

  • dragonfly
CWE
CWE-392

Missing Report of Error Condition

NVD-CWE-noinfo