Executive brief
OpenCanary is a honeypot tool used to detect unauthorized activity on a network by mimicking real services. A vulnerability in its MongoDB module allows a remote attacker to crash or freeze the service using a single specially crafted network packet. This results in a denial-of-service, preventing the honeypot from performing its security monitoring functions.
Technical details
A denial-of-service vulnerability exists in the MongoDB module of OpenCanary version 0.9.8. The flaw is rooted in improper input validation (CWE-20) and an infinite loop condition (CWE-835) triggered by a single malicious packet. When exploited, the Twisted process consumes 100% of the available CPU core, leading to excessive resource allocation and service unavailability. The vulnerability is reachable over the network without authentication. The issue is resolved in version 0.9.9; users unable to upgrade can mitigate the risk by disabling the MongoDB module in the configuration file.
Affected products
- Thinkst Applied Research OpenCanary 0.9.8
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory
- 2026-07-22: patched: Fixed in version 0.9.9