CVE-2025-26269

Severity CVSS v4.0:
Pending analysis
Type:
CWE-191 Integer Underflow (Wrap or Wraparound)
Publication date:
17/04/2025
Last modified:
11/07/2025

Description

DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dragonflydb:dragonfly:*:*:*:*:*:*:*:* 1.29.0 (excluding)