Integer Overflow Vulnerability in DragonflyDB by Dragonfly
CVE-2025-52935

9.4CRITICAL

Key Information:

Status
Vendor
CVE Published:
23 June 2025

What is CVE-2025-52935?

An integer overflow vulnerability has been identified in the DragonflyDB, specifically within the lua_struct.C program files. This flaw may allow attackers to exploit data mismanagement within the application, potentially leading to unexpected behavior. Affected versions include DragonflyDB 1.30.1, 1.30.0, and 1.28.18. It's crucial for users to apply the necessary patches to maintain data integrity and ensure secure operations.

Affected Version(s)

dragonfly 1.30.1

dragonfly 1.30.0

dragonfly 1.28.18

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TITAN Team ([email protected])
.