2.3
/ 10
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Description
Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer. An authenticated user can inject arbitrary RESP messages into the connection's response stream, potentially causing response desynchronization in connection-pool clients. This vulnerability is fixed in 1.39.9.
Basic Information
ID
CVE-2026-47206
Source
GitHub_M
Published
Jun 26, 2026 at 16:39
Modified
Jun 26, 2026 at 17:31
Affected Product
Vendor
dragonflydb
Product
dragonfly
Version
< 1.38.9
Affected Versions
dragonflydb dragonfly < 1.38.9