Integer Overflow Vulnerability in DragonflyDB by Dragonfly
CVE-2025-52935
9.4CRITICAL
What is CVE-2025-52935?
An integer overflow vulnerability has been identified in the DragonflyDB, specifically within the lua_struct.C program files. This flaw may allow attackers to exploit data mismanagement within the application, potentially leading to unexpected behavior. Affected versions include DragonflyDB 1.30.1, 1.30.0, and 1.28.18. It's crucial for users to apply the necessary patches to maintain data integrity and ensure secure operations.
Affected Version(s)
dragonfly 1.30.1
dragonfly 1.30.0
dragonfly 1.28.18
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
TITAN Team ([email protected])