Security: dragonflydb/dragonfly
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
-
Malformed hash/zset listpack in an RDB image crashes the server and can leak heap memoryGHSA-pmgx-g74v-v37g published
Sep 23, 2026 by romangeModerate -
Unauthenticated remote code execution in DragonflyDB (memcached reply-builder heap overflow)GHSA-9q98-cx72-pg45 published
Sep 20, 2026 by romangeModerate -
Unauthenticated remote code execution in DragonflyDB (stack buffer overflow in `CompactObj::HashCode()`)GHSA-f4g8-vhw4-36xm published
Sep 20, 2026 by romangeLow -
DragonflyDB stream RDB deserialization double-free (CWE-415)GHSA-cg35-6jf4-crfh published
Sep 20, 2026 by romangeModerate -
DragonflyDB `CMS.INITBYDIM` integer overflow leads to a remote, attacker-controlled heap out-of-bounds writeGHSA-cmmv-h748-v93x published
Jul 15, 2026 by romangeModerate -
RESTORE operations may crash the serverGHSA-cwjr-j869-h8q9 published
Jun 15, 2026 by romangeModerate -
RESP Protocol Injection via Lua redis.error_reply() in EvalSerializerGHSA-h77h-c6hc-qc9h published
May 19, 2026 by romangeLow
Learn more about advisories related to dragonflydb/dragonfly in the GitHub Advisory Database