DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.
2025-04-17T18:15:48.870
2025-04-25T16:33:11.420
Analyzed
CVSSv3.1: 3.3 (LOW)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | dragonflydb | dragonfly | < 1.27.0 | Yes |