low · CVSS v3 3.7
CVE-2026-85219
Thinkst Canary's OpenCanary 0.9.9 contains a Redis module flaw that lets an unauthenticated attacker trigger a denial-of-service by exhausti
Overview
Thinkst Canary's OpenCanary 0.9.9 contains a Redis module flaw that lets an unauthenticated attacker trigger a denial-of-service by exhausting memory. The issue can be exploited remotely without credentials. It affects deployments running the default Redis module.
Description
Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause unconstrained memory usage.
Impact
The vulnerability causes uncontrolled memory consumption, leading to service crashes and loss of monitoring availability. Defenders managing OpenCanary instances risk downtime and reduced visibility into network activity. The impact is limited to availability, not confidentiality or integrity.
Remediation
Upgrade OpenCanary to version 0.9.10 or later where the Redis module is patched. If an upgrade is not immediately possible, disable the Redis module or restrict its network exposure with firewall rules. Monitor system memory usage and set alerts for abnormal growth.
Risk context
Severity is low with a CVSS v3 score of 3.7. No EPSS data is available, indicating a moderate but not urgent risk. Defenders should address it in routine patch cycles.
Affected products
- Thinkst Canary OpenCanary 0.9.9
- Thinkst Canary
Scores
- Severity
- low
- CVSS v2
- 2.6
- CVSS v3
- 3.7
- CVSS v4
- —
- EPSS
- —