Vulnerabilities > CVE-2025-26268 - Unspecified vulnerability in Dragonflydb Dragonfly

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
dragonflydb

Summary

DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.

Vulnerable Configurations

Part Description Count
Application
Dragonflydb
89