CVE-2026-85219: Denial-of-Service in the OpenCanary Redis service
Published Sep 21, 2026
·Updated
Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause unconstrained memory usage.
Affected Software
2 affected components
Thinkst Canary OpenCanary=0.9.9
redis/OpenCanary Redis service
Event History
Sep 21, 2026
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated remote attacker can exploit the issue if they can reach the OpenCanary Redis service over the network.
2
What is the impact of successful exploitation?
Successful exploitation can cause unconstrained memory usage in the Redis module, resulting in a denial of service.
3
Which version is identified as affected?
The reported affected version is Thinkst Canary OpenCanary 0.9.9.