Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3192 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-54341EXPLOITEDPATCHED
dragonflydb · dragonfly

Dragonfly: RESTORE operations may crash the server

Description

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload triggers an out-of-bounds read in DragonflyDB's listpack collection loaders, crashing the entire server process (SIGSEGV). Because DragonflyDB requires no authentication by default and RESTORE is a normal keyspace command, an unauthenticated remote attacker can crash the server with a single ~24-byte command — a remote, repeatable denial of service. This vulnerability is fixed in 1.39.0.

Affected Products

VendorProductVersions
dragonflydbdragonfly< 1.39.0

References

  • https://github.com/dragonflydb/dragonfly/security/advisories/GHSA-cwjr-j869-h8q9(x_refsource_CONFIRM)
  • https://github.com/dragonflydb/dragonfly/pull/7502(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB1d ago
CVE-2026-54341 | dragonflydb dragonfly up to 1.38.x RESTORE out-of-bounds
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
1.39.0
CWECWE-125
PublishedJun 26, 2026
Last enriched1d agov2
Trending Score54
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (1)

NONECVE-2026-47206
Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer
Trending: 25

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 26, 2026
Discovered by ZDM
Jun 26, 2026
Updated: affectedVersions, severity, activelyExploited, patchAvailable
Jun 26, 2026
Actively Exploited
Jun 26, 2026
Patch Available
Jun 26, 2026

Version History

v2
Last enriched 1d ago
v2Tier C1d ago

Updated affected versions to 1.38.x, changed severity to MEDIUM, and noted that no exploit is available.

affectedVersionsseverityactivelyExploitedpatchAvailable
via VulDB
v11d ago

Initial creation