CVE-2025-26268
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 17, 2025
Updated: Apr 25, 2025
CWE ID 392
Summary
CVE-2025-26268 is a denial-of-service vulnerability affecting DragonflyDB Dragonfly before version 1.27.0. Authenticated users can exploit this issue by crafting malicious Redis commands that cause the daemon to crash, resulting in a denial-of-service condition. The root cause of the vulnerability lies in the failure to adequately verify the validity of the scan cursor before processing these commands.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.