CVE-2025-26269
LOWDragonflyDB Dragonfly < 1.29.0 - Authenticated Denial of Service via Lua Library Integer Underflow
Title source: llmDescription
DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.
References (3)
Core 3
Core References
Exploit, Third Party Advisory
https://gist.github.com/ankki-zsyang/d8215cf6e868d07546eaa5346a884ebd
Exploit, Issue Tracking, Patch
https://github.com/dragonflydb/dragonfly/issues/4468
Scores
CVSS v3
3.3
EPSS
0.0023
EPSS Percentile
13.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-191
Status
published
Products (1)
dragonflydb/dragonfly
< 1.29.0
Published
Apr 17, 2025
Tracked Since
Feb 18, 2026