Executive brief
Dragonfly is a high-performance data store used to manage application data in memory. A security flaw allows an authenticated user to manipulate the server's communication protocol by including special characters in Lua scripts. This can lead to "response desynchronization," where a database client receives the wrong answer to a query, potentially causing application errors or data corruption in environments where multiple users share the same connection pool.
Technical details
A RESP Protocol Injection vulnerability exists in Dragonfly's EvalSerializer component. The root cause is the failure of `EvalSerializer::OnError()` and `OnStatus()` to sanitize carriage return and line feed (\r\n) sequences in strings returned by Lua's `redis.error_reply()` and `redis.status_reply()` functions. Because RESP uses CRLF as a frame delimiter, an authenticated attacker can inject arbitrary RESP messages into the response stream. This can lead to response desynchronization, where a client using a connection pool misinterprets an injected message as the response to a subsequent, unrelated command. The issue is fixed in version 1.39.9 by stripping CRLF characters from Lua-controlled strings before they are sent to the reply builder.
Affected products
- DragonflyDB Dragonfly < 1.39.9
Timeline
- 2026-05-18: disclosed: Issue reported on GitHub
- 2026-05-18: patched: Fix merged into main branch
- 2026-06-26: advisory: CVE published