Denial-of-Service in the Thinkst Canary Redis service
Summary
| CVE | CVE-2026-85220 |
|---|---|
| State | PUBLISHED |
| Assigner | ThinkstAppliedResearch |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-21 14:17:22 UTC |
| Updated | 2026-09-22 19:41:38 UTC |
| Description | A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. The Canary is NOT affected if the Redis service is disabled. Thinkst has addressed this issue on all supported platforms. New update files to address this issue are available on all platforms except Docker. For Docker customers, a new Docker image has been published which includes the patch. Customers with automatic updates enabled already have updates in distribution. If automatic updates are disabled, customers are advised to update their Canaries. Workarounds are available for customers unable to update at this time. |
Risk And Classification
Primary CVSS: v3.1 3.7 LOW from 0f2be0ad-3469-4e56-b38f-4eb96719b425
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS: 0.002540000 probability, percentile 0.173150000 (date 2026-09-23)
Problem Types: CWE-770 | CWE-770 CWE-770 Allocation of resources without limits or throttling
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 0f2be0ad-3469-4e56-b38f-4eb96719b425 | Secondary | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
| 3.1 | CNA | CVSS | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Thinkst Applied Research | Canary | unaffected 5.1.2 custom | Not specified |
| CNA | Thinkst Applied Research | Canary | unaffected 5.2.2 custom | Not specified |
| CNA | Thinkst Applied Research | Canary | unaffected 5.3.2 custom | Not specified |
| CNA | Thinkst Applied Research | Canary | unaffected 5.4.2 custom | Not specified |
| CNA | Thinkst Applied Research | Canary | unaffected 5.5.2 custom | Not specified |
| CNA | Thinkst Applied Research | Canary | unaffected 5.6.4 custom | Not specified |
| CNA | Thinkst Applied Research | Canary | unaffected 5.7.2 custom | Not specified |
| CNA | Thinkst Applied Research | Canary | unaffected 5.8.2 custom | Not specified |
| CNA | Thinkst Applied Research | Canary | unaffected 5.9.2 custom | Not specified |
| CNA | Thinkst Applied Research | Canary | unaffected 5.10.2 custom | Not specified |
| CNA | Thinkst Applied Research | Canary | unaffected 5.11.2 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| canary.tools/security-advisories/tc-2026-01.txt | 0f2be0ad-3469-4e56-b38f-4eb96719b425 | canary.tools | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Teddy Thobane (rootkiTed) (en)
Additional Advisory Data
Solutions
CNA: Canary is available across multiple platforms, each with its own version number. The table below shows the first affected and patched versions for all Canary platforms. Platform | First Vulnerable Canary Release | First Fixed Canary Release ------------------+---------------------------------+---------------------------- AWS EC2 | 2.0.2 | 5.3.2 Docker | 3.7.1 | 5.7.2 GCP | 2.2.3 | 5.4.2 Hardware | 1.0 | 5.1.2 Microsoft Azure | 2.2.9 | 5.6.4 Microsoft Hyper-V | 2.3.2 | 5.5.2 Nutanix | 4.9.0 | 5.9.2 OCI | 3.11.10 | 5.11.2 OpenStack | 3.8.9 | 5.8.2 Tailscale | 2.2.1 | 5.3.2 VMware ESXi | 2.0.2 | 5.2.2
Workarounds
CNA: * Disable the Redis service