CVE Vulnerabilities

CVE-2025-26268

Missing Report of Error Condition

Published: Apr 17, 2025 | Modified: Apr 25, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.

Weakness

The product encounters an error but does not provide a status code or return value to indicate that an error has occurred.

Affected Software

Name Vendor Start Version End Version
Dragonfly Dragonflydb * 1.27.0 (excluding)

References