Dragonflydb maintains a focused in-memory data store product positioned as an alternative to Redis, with its vulnerability profile centered on a narrow but operationally critical codebase. The observed weakness classes, including integer underflow conditions and missing error handling, reflect the low-level data-structure and memory-management demands of high-performance caching systems. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dragonflydb over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-26268MEDIUM DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not chec | Apr 17, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-26269MEDIUM DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large nega | Apr 17, 2025 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dragonflydb.
Media articles that mention a CVE ID that affects a product developed by Dragonflydb — matched by CVE ID, not by vendor name.