Denial-of-Service Vulnerability in Thinkst Canary's OpenCanary
CVE-2026-85219

3.7LOW

Key Information:

Vendor
CVE Published:
21 September 2026

What is CVE-2026-85219?

A Denial-of-Service vulnerability has been identified in the Redis module of Thinkst Canary's OpenCanary version 0.9.9. This flaw allows an unauthenticated remote attacker to exploit the system, leading to uncontrolled memory consumption. Consequently, this may result in service disruptions or degraded performance, affecting the overall integrity and availability of the service.

Affected Version(s)

OpenCanary 0.4 < 0.9.10

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Teddy Thobane (rootkiTed)
.