Junglewise Threat Intelligence

CVE-2026-47206: DragonflyDB Dragonfly RESP protocol injection in EvalSerializer

CVE-2026-47206 · Severity: info · CVSS 2.3 · Published 2026-06-26

Executive brief

Dragonfly is a high-performance data store used to manage application data in memory. A security flaw allows an authenticated user to manipulate the server's communication protocol by including special characters in Lua scripts. This can lead to "response desynchronization," where a database client receives the wrong answer to a query, potentially causing application errors or data corruption in environments where multiple users share the same connection pool.

Technical details

A RESP Protocol Injection vulnerability exists in Dragonfly's EvalSerializer component. The root cause is the failure of `EvalSerializer::OnError()` and `OnStatus()` to sanitize carriage return and line feed (\r\n) sequences in strings returned by Lua's `redis.error_reply()` and `redis.status_reply()` functions. Because RESP uses CRLF as a frame delimiter, an authenticated attacker can inject arbitrary RESP messages into the response stream. This can lead to response desynchronization, where a client using a connection pool misinterprets an injected message as the response to a subsequent, unrelated command. The issue is fixed in version 1.39.9 by stripping CRLF characters from Lua-controlled strings before they are sent to the reply builder.

Affected products

  • DragonflyDB Dragonfly < 1.39.9

Timeline

  • 2026-05-18: disclosed: Issue reported on GitHub
  • 2026-05-18: patched: Fix merged into main branch
  • 2026-06-26: advisory: CVE published

References

Related threats