Denial-of-Service Vulnerability in Thinkst Canary Honeypot Redis Service
CVE-2026-85220
3.7LOW
What is CVE-2026-85220?
A vulnerability exists in the Thinkst Canary honeypot's Redis service that could enable an unauthenticated remote attacker to perform a Denial-of-Service attack. This situation arises when the Redis service is enabled. However, if the Redis service is disabled, the Canary remains unaffected. Thinkst has issued updates for all supported platforms, and Docker customers have access to a new image that rectifies the issue. For users with automatic updates enabled, patches are already being distributed. Those with disabled automatic updates are encouraged to manually update their Canaries. Temporary workarounds are also available for customers who cannot update immediately.
Affected Version(s)
Canary 5.1.2
Canary 5.2.2
Canary 5.3.2
