CVE-2025-26268

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 17, 2025
Updated: Apr 25, 2025
CWE ID 392

Summary

CVE-2025-26268 is a denial-of-service vulnerability affecting DragonflyDB Dragonfly before version 1.27.0. Authenticated users can exploit this issue by crafting malicious Redis commands that cause the daemon to crash, resulting in a denial-of-service condition. The root cause of the vulnerability lies in the failure to adequately verify the validity of the scan cursor before processing these commands.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share