Denial of Service Vulnerability in DragonflyDB by Dragonfly
CVE-2026-54341
7.5HIGH
What is CVE-2026-54341?
DragonflyDB, an in-memory data store designed for modern application workloads, contains a vulnerability in its handling of RESTORE commands prior to version 1.39.0. An attacker can exploit this issue by sending a specially crafted RESTORE payload, resulting in an out-of-bounds read that may crash the server process. This vulnerability allows unauthenticated remote attackers to trigger a denial of service condition, making the server unavailable with a minimal command size, highlighting the importance of keeping the software updated to the latest version.
Affected Version(s)
dragonfly < 1.39.0
