Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whose width times depth times sizeof(int64_t) overflows in src/core/cms.cc, allocating an undersized counter buffer while CMS.INCRBY and CMS.QUERY use the unbounded dimensions, which allows an unauthenticated remote client to corrupt or disclose adjacent heap memory and crash the server. This issue is fixed in version 1.40.0.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-190"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62357.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62357.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "211610076406049177367758484044134809698",
"length": 287
},
"id": "CVE-2026-62357-3b5bafbf",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
"target": {
"file": "src/core/cms.cc",
"function": "CMS::CMS"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"5322635667862774704304786385451744388",
"66886196783674913294619631552708341386",
"198048368828082106981029993325006176787",
"240006315924978351772453842259916650506",
"175523457867972427676949757412211360294",
"208091916101434163357341777078200311244"
],
"threshold": 0.9
},
"id": "CVE-2026-62357-5b3a11ff",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
"target": {
"file": "src/server/cms_family_test.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"130585936608604658303845166766116616892",
"107885826254918782674890319872812989855",
"143323120089058282586446172549854694237",
"215020614655049150903180848810109972302"
],
"threshold": 0.9
},
"id": "CVE-2026-62357-6859d390",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
"target": {
"file": "src/server/rdb_load.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"326546988665989418964483679692296212787",
"261294368370366211537486739996430458843",
"54577035639197598498529811661805438661",
"226262520547116664413642351007982759195",
"82003264845782041763169129325436076432",
"22908802087225016360846923035840620791",
"249870577877748641218662543289235468688",
"204528849240036080322805419595189127645",
"236289811163365274349986478566039298228",
"181015966572041289815382278999968256739",
"299842543910091958129801951071722602752",
"109471931642327954755727622604190447627",
"252721095131456832356784285004118551663",
"180483997014715746735996915159310832760",
"226507359704114734751633079389011690922",
"172608647554937876326735470700110418312"
],
"threshold": 0.9
},
"id": "CVE-2026-62357-6d623a05",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
"target": {
"file": "src/core/cms.cc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "268523874514195481247651679642540955047",
"length": 133
},
"id": "CVE-2026-62357-74803e9e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
"target": {
"file": "src/core/cms.cc",
"function": "CMS::~CMS"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "166458192596899558720045250913960581656",
"length": 875
},
"id": "CVE-2026-62357-7ce73c65",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
"target": {
"file": "src/server/cms_family.cc",
"function": "CmdInitByProb"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "108142728200635670846621813511368675497",
"length": 998
},
"id": "CVE-2026-62357-822e27c3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
"target": {
"file": "src/server/rdb_load.cc",
"function": "RdbLoaderBase::ReadCMS"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"126266558296851872821442021129732622758",
"309387694038384607946984148821318057030",
"18383488015668467856844079310516349067",
"195143117881872716203820970696667162848",
"11583402942871686552239329101928941686"
],
"threshold": 0.9
},
"id": "CVE-2026-62357-8f6c6fd4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/e4ebd87e85c011f72aa646942ef87b8703d3443b",
"target": {
"file": "src/server/db_slice.cc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "95380582024133472853688761177186158628",
"length": 554
},
"id": "CVE-2026-62357-af9ef26d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/e4ebd87e85c011f72aa646942ef87b8703d3443b",
"target": {
"file": "src/server/db_slice.cc",
"function": "AccountObjectMemory"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "301254880437537105958376890331129291847",
"length": 751
},
"id": "CVE-2026-62357-b57bca8f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
"target": {
"file": "src/server/cms_family.cc",
"function": "CmdInitByDim"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "16180070476676575682002681068948326393",
"length": 469
},
"id": "CVE-2026-62357-d1d4c91e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
"target": {
"file": "src/server/cms_family.cc",
"function": "OpInitByProb"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "182576966063876680064100708485032424839",
"length": 1650
},
"id": "CVE-2026-62357-d8021478",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
"target": {
"file": "src/server/topk_family.cc",
"function": "TopkFamily::Reserve"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"148277050649825178915387525857206898407",
"315436223152657796052384274298663642190",
"135743326164093846698374518920218787069",
"115447363404704727468888404907224893651",
"136524342585533875305528799996635351461",
"301611135868608418012681345338576202008",
"160769278250656544163410210139617439912",
"114289193372147066870793584892279924938",
"322343239175857834490837910609154567452",
"265784978133679873744335278281760551279",
"314670208432417967780790740430318228557",
"94505295605800288117724702057635664075",
"48800843734390190077056865420641090106",
"285921644338427037669958508481122937928",
"191821388118054824332906545998702857912",
"31245848844017292033289131401794918008",
"83532725745478892386170748535994092904",
"70968742688256471497972680291448361598",
"302474930139706989704278046162807116661",
"128261498888540707934566869093157962171",
"92137815719616682395720206275223817185",
"133375864684157095368624552481248038128",
"231287147525687936074629205088962259729",
"266964488576513742250662735561227632394",
"194690155019045898659920869462698146137",
"260101508465618993661690390557611114997",
"100115118831813957715884167788758966071",
"320832550988267212069920672357553571996",
"339024042150671829238856488417419542774",
"273366004019004435328688306775340605115",
"111036665116251170690313608029839477610",
"194569545872976801223483719096244946897"
],
"threshold": 0.9
},
"id": "CVE-2026-62357-e2b14714",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
"target": {
"file": "src/server/cms_family.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"237816498549518553439389218087208171782",
"257287862434300888839049252140650834095",
"148190579141667079587705847378621052081",
"340145901237256693308061158817851349701",
"180557762326646257468783137732033542896",
"211850758799689948451466074768285394397"
],
"threshold": 0.9
},
"id": "CVE-2026-62357-f4b7777d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
"target": {
"file": "src/server/topk_family.cc"
}
}
]
"2026-09-12T08:08:20Z"