rootpwn

low · CVSS v3 3.7

CVE-2026-85219

Thinkst Canary's OpenCanary 0.9.9 contains a Redis module flaw that lets an unauthenticated attacker trigger a denial-of-service by exhausti

Overview

Thinkst Canary's OpenCanary 0.9.9 contains a Redis module flaw that lets an unauthenticated attacker trigger a denial-of-service by exhausting memory. The issue can be exploited remotely without credentials. It affects deployments running the default Redis module.

Description

Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause unconstrained memory usage.

Impact

The vulnerability causes uncontrolled memory consumption, leading to service crashes and loss of monitoring availability. Defenders managing OpenCanary instances risk downtime and reduced visibility into network activity. The impact is limited to availability, not confidentiality or integrity.

Remediation

Upgrade OpenCanary to version 0.9.10 or later where the Redis module is patched. If an upgrade is not immediately possible, disable the Redis module or restrict its network exposure with firewall rules. Monitor system memory usage and set alerts for abnormal growth.

Risk context

Severity is low with a CVSS v3 score of 3.7. No EPSS data is available, indicating a moderate but not urgent risk. Defenders should address it in routine patch cycles.

Affected products

  • Thinkst Canary OpenCanary 0.9.9
  • Thinkst Canary

Scores

Severity
low
CVSS v2
2.6
CVSS v3
3.7
CVSS v4
EPSS

DoS Redis OpenCanary Memory LowSeverity DenialOfService

← All CVEs