CVE-2026-85220
3.7 LOWPublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The vulnerability allows unauthenticated attackers to perform a Denial-of-Service attack on the Thinkst Canary honeypot Redis service by exploiting its enabled state.
- Exploitability
- Exploitation requires the Redis service to be enabled, making it moderately difficult. No specific technical skills are required beyond basic network access.
- Blast radius
- If exploited, this could lead to service disruption of the affected Thinkst Canary honeypot instances.
- Prioritized remediation
- Disable the Redis service on all affected Canaries immediately.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. The Canary is NOT affected if the Redis service is disabled. Thinkst has addressed this issue on all supported platforms. New update files to address this issue are available on all platforms except Docker. For Docker customers, a new Docker image has been published which includes the patch. Customers with automatic updates enabled already have updates in distribution. If automatic updates are disabled, customers are advised to update their Canaries. Workarounds are available for customers unable to update at this time.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Weaknesses
CWE-770
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- LOWCVE-2026-85219PoC
- HIGHCVE-2026-88406PoC
- HIGHCVE-2026-88407PoC
- MEDIUMCVE-2026-88408PoC
- HIGHCVE-2026-88409PoC
- HIGHCVE-2026-88411PoC
- MEDIUMCVE-2026-88412PoC
- HIGHCVE-2026-61629PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.