First published: Thu Apr 17 2025(Updated: )
DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DragonflyDB Dragonfly | <=1.28.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26269 has been classified as a denial of service vulnerability.
To fix CVE-2025-26269, upgrade DragonflyDB Dragonfly to version 1.28.3 or later.
CVE-2025-26269 affects all authenticated users of DragonflyDB Dragonfly versions up to and including 1.28.2.
CVE-2025-26269 enables authenticated users to execute a Lua library command that crashes the daemon.
Yes, CVE-2025-26269 is related to the specific implementation of Lua library commands in DragonflyDB.