CVE-2025-26269

DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.
Configurations

No configuration.

History

23 Apr 2025, 16:15

Type Values Removed Values Added
References () https://github.com/dragonflydb/dragonfly/issues/4468 - () https://github.com/dragonflydb/dragonfly/issues/4468 -

22 Apr 2025, 18:15

Type Values Removed Values Added
References
  • () https://gist.github.com/ankki-zsyang/d8215cf6e868d07546eaa5346a884ebd -
Summary
  • (es) DragonflyDB Dragonfly hasta la versión 1.28.2 permite a los usuarios autenticados provocar una denegación de servicio (falla del daemon) a través de un comando de la librería Lua que hace referencia a un entero negativo grande.
Summary (en) DragonflyDB Dragonfly through 1.28.2 allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer. (en) DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.

17 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-17 18:15

Updated : 2025-04-23 16:15


NVD link : CVE-2025-26269

Mitre link : CVE-2025-26269

CVE.ORG link : CVE-2025-26269


JSON object : View

Products Affected

No product.

CWE
CWE-191

Integer Underflow (Wrap or Wraparound)