Description
Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause unconstrained memory usage.
Published: 2026-09-21
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: Denial-of-Service
Action: Disable Redis
AI Analysis

Impact

Thinkst Applied Research’s OpenCanary 0.9.9 contains a denial‑of‑service vulnerability in the Redis module that allows an unauthenticated remote attacker to trigger unconstrained memory usage, exhausting system resources and rendering the service unavailable. The flaw resides in improper handling of memory allocation requests, resulting in overuse of memory and potential process termination. Based on the description, the likely attack vector is a remote, unauthenticated network connection to the exposed Redis interface, although the class of the weakness is a rating of CVSS 3.7 which indicates moderate severity.

Affected Systems

The affected vendor is Thinkst Applied Research and the product is OpenCanary. The vulnerability is present in OpenCanary version 0.9.9. No other product or version information is provided.

Risk and Exploitability

The CVSS score of 3.7 reflects the moderate impact of the denial‑of‑service condition. Exploitation requires the Redis module to be enabled and externally reachable; no authentication or privileges are needed. An attacker can repeatedly send specially crafted commands to flood memory, causing the service to crash or become unresponsive. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that while the risk is real, there is currently no known widespread exploitation.

Generated by OpenCVE AI on September 21, 2026 at 20:21 UTC.

Remediation

Vendor Workaround

Disable the Redis module.


OpenCVE Recommended Actions

  • Disable the Redis module in the OpenCanary configuration or stop its service.
  • Upgrade OpenCanary to the latest patched release once the vendor issues a fix.
  • Restrict external access to the OpenCanary host using firewall rules to limit connections to the Redis port.

Generated by OpenCVE AI on September 21, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Thinkst Applied Research
Thinkst Applied Research opencanary
Vendors & Products Thinkst Applied Research
Thinkst Applied Research opencanary

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause unconstrained memory usage.
Title Denial-of-Service in the OpenCanary Redis service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Thinkst Applied Research Opencanary
cve-icon MITRE

Status: PUBLISHED

Assigner: ThinkstAppliedResearch

Published:

Updated: 2026-09-21T19:39:43.314Z

Reserved: 2026-09-03T14:04:45.649Z

Link: CVE-2026-85219

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-21T20:17:36.807

Modified: 2026-09-21T20:17:36.807

Link: CVE-2026-85219

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T20:30:18Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling