PatchSiren

dragonflydb CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH dragonflydb CVE published 2026-08-18

CVE-2026-62357

CVE-2026-62357 is a high-severity vulnerability in Dragonfly, an in-memory data store. The vulnerability allows an unauthenticated remote client to corrupt or disclose adjacent heap memory and crash the server. It is fixed in version 1.40.0. Defenders should assess exposure and prioritize patching to prevent potential memory corruption and server crashes. The vulnerability is caused by the CMS.INITBYDIM a [truncated]