CVE-2026-85220
Received Received - Intake

Denial-of-Service in Thinkst Canary Redis Service

Vulnerability report for CVE-2026-85220, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: ThinkstAppliedResearch

Description

A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. The Canary is NOT affected if the Redis service is disabled. Thinkst has addressed this issue on all supported platforms. New update files to address this issue are available on all platforms except Docker. For Docker customers, a new Docker image has been published which includes the patch. Customers with automatic updates enabled already have updates in distribution. If automatic updates are disabled, customers are advised to update their Canaries. Workarounds are available for customers unable to update at this time.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-21
AI Q&A
2026-09-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
thinkst canary to 2026-09-21 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Denial-of-Service vulnerability in the Thinkst Canary honeypot's Redis service. It allows an unauthenticated remote attacker to disrupt the honeypot's functionality when the Redis service is enabled. The vulnerability does not affect systems where the Redis service is disabled.

Detection Guidance

To detect this vulnerability, check if the Redis service is enabled on your Thinkst Canary honeypot. If Redis is running, the system is potentially vulnerable. Use commands like 'systemctl status redis' or 'ps aux | grep redis' to verify Redis service status.

Impact Analysis

The impact is limited to disruption of the honeypot's functionality when Redis is enabled. It does not allow data theft or code execution. The honeypot becomes unavailable to attackers, reducing its effectiveness in detecting intrusions.

Compliance Impact

This vulnerability does not directly impact compliance with standards like GDPR or HIPAA as it only causes a Denial-of-Service on the honeypot Redis service. Compliance depends on the broader system configuration and data handling practices, not this specific issue.

Mitigation Strategies

Immediately disable the Redis service if enabled. Update your Canary to the latest version or apply the provided patch. For Docker users, pull the new container image. If updates are not possible, apply the workaround by disabling Redis.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85220. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart