Impact
Thinkst Applied Research’s OpenCanary 0.9.9 contains a denial‑of‑service vulnerability in the Redis module that allows an unauthenticated remote attacker to trigger unconstrained memory usage, exhausting system resources and rendering the service unavailable. The flaw resides in improper handling of memory allocation requests, resulting in overuse of memory and potential process termination. Based on the description, the likely attack vector is a remote, unauthenticated network connection to the exposed Redis interface, although the class of the weakness is a rating of CVSS 3.7 which indicates moderate severity.
Affected Systems
The affected vendor is Thinkst Applied Research and the product is OpenCanary. The vulnerability is present in OpenCanary version 0.9.9. No other product or version information is provided.
Risk and Exploitability
The CVSS score of 3.7 reflects the moderate impact of the denial‑of‑service condition. Exploitation requires the Redis module to be enabled and externally reachable; no authentication or privileges are needed. An attacker can repeatedly send specially crafted commands to flood memory, causing the service to crash or become unresponsive. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that while the risk is real, there is currently no known widespread exploitation.
OpenCVE Enrichment