rootpwn

low · CVSS v3 3.7

CVE-2026-85220

Thinkst Canary honeypots with the Redis service enabled are vulnerable to an unauthenticated remote denial‑of‑service attack. The flaw allow

Overview

Thinkst Canary honeypots with the Redis service enabled are vulnerable to an unauthenticated remote denial‑of‑service attack. The flaw allows attackers to crash the Redis process, disrupting the honeypot’s availability. Thinkst has released patches for all supported platforms, including a new Docker image.

Description

A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. The Canary is NOT affected if the Redis service is disabled. Thinkst has addressed this issue on all supported platforms. New update files to address this issue are available on all platforms except Docker. For Docker customers, a new Docker image has been published which includes the patch. Customers with automatic updates enabled already have updates in distribution. If automatic updates are disabled, customers are advised to update their Canaries. Workarounds are available for customers unable to update at this time.

Impact

The vulnerability compromises the availability of the honeypot, potentially causing false negatives in threat detection. Defenders relying on Canary for early warning may experience service interruptions. The attack does not grant access to data or control beyond DoS.

Remediation

Apply the latest firmware update or Docker image released by Thinkst. If automatic updates are enabled, the system will update automatically. If disabled, manually download and install the update or disable the Redis service. Workarounds are available for customers unable to update immediately.

Risk context

Severity is low with a CVSS v3 score of 3.7 and no EPSS data. The risk is limited to availability disruption, and the patch is readily available.

Affected products

  • Thinkst Canary

Scores

Severity
low
CVSS v2
2.6
CVSS v3
3.7
CVSS v4
EPSS

Denial of Service Redis Honeypot Thinkst Canary Low Severity Patch

← All CVEs