Dragonflydb

Dragonfly

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 18.08.2026 15:18:52
  • Zuletzt bearbeitet 19.08.2026 15:17:21

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whose width times depth times sizeof(int64_t) overflows in src/core/cms.cc, allocating an undersized coun...

  • EPSS 0.4%
  • Veröffentlicht 26.06.2026 16:42:15
  • Zuletzt bearbeitet 26.06.2026 20:20:22

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload triggers an out-of-bounds read in DragonflyDB's listpack collection loaders, crashing the entire server process (SIGSEGV). Because...

  • EPSS 0.28%
  • Veröffentlicht 26.06.2026 16:39:27
  • Zuletzt bearbeitet 26.06.2026 20:20:22

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer. An authenticated user can inject arbitrary RESP messages into the con...

  • EPSS 0.36%
  • Veröffentlicht 23.06.2025 09:27:18
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Integer Overflow or Wraparound vulnerability in dragonflydb dragonfly (src/redis/lua/struct modules). This vulnerability is associated with program files lua_struct.C. This issue affects dragonfly: 1.30.1, 1.30.0, 1.28.18.

Exploit
  • EPSS 0.38%
  • Veröffentlicht 17.04.2025 00:00:00
  • Zuletzt bearbeitet 25.04.2025 16:33:11

DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 17.04.2025 00:00:00
  • Zuletzt bearbeitet 11.07.2025 16:36:33

DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.