← Back to search

CVE-2026-85220

3.7 LOW

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The vulnerability allows unauthenticated attackers to perform a Denial-of-Service attack on the Thinkst Canary honeypot Redis service by exploiting its enabled state.
Exploitability
Exploitation requires the Redis service to be enabled, making it moderately difficult. No specific technical skills are required beyond basic network access.
Blast radius
If exploited, this could lead to service disruption of the affected Thinkst Canary honeypot instances.
Prioritized remediation
Disable the Redis service on all affected Canaries immediately.
dosredishoneypotservice-disabled

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. The Canary is NOT affected if the Redis service is disabled. Thinkst has addressed this issue on all supported platforms. New update files to address this issue are available on all platforms except Docker. For Docker customers, a new Docker image has been published which includes the patch. Customers with automatic updates enabled already have updates in distribution. If automatic updates are disabled, customers are advised to update their Canaries. Workarounds are available for customers unable to update at this time.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses

CWE-770

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.