๐Ÿ” CVE Alert

CVE-2026-85220

LOW 3.7

Denial-of-Service in the Thinkst Canary Redis service

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. The Canary is NOT affected if the Redis service is disabled. Thinkst has addressed this issue on all supported platforms. New update files to address this issue are available on all platforms except Docker. For Docker customers, a new Docker image has been published which includes the patch. Customers with automatic updates enabled already have updates in distribution. If automatic updates are disabled, customers are advised to update their Canaries. Workarounds are available for customers unable to update at this time.

CWE CWE-770
Vendor thinkst applied research
Product canary
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for thinkst applied research canary

Be the first to know when new low vulnerabilities affecting thinkst applied research canary are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

Thinkst Applied Research / Canary
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
canary.tools: https://canary.tools/security-advisories/tc-2026-01.txt

Credits

Teddy Thobane (rootkiTed)