CVE-2026-62357

Source
https://cve.org/CVERecord?id=CVE-2026-62357
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62357.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-62357
Aliases
  • GHSA-cmmv-h748-v93x
Published
2026-08-18T15:18:52Z
Modified
2026-09-12T08:08:20Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
DragonflyDB `CMS.INITBYDIM` integer overflow leads to a remote, attacker-controlled heap out-of-bounds write
Details

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whose width times depth times sizeof(int64_t) overflows in src/core/cms.cc, allocating an undersized counter buffer while CMS.INCRBY and CMS.QUERY use the unbounded dimensions, which allows an unauthenticated remote client to corrupt or disclose adjacent heap memory and crash the server. This issue is fixed in version 1.40.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-190"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62357.json"
}
References

Affected packages

Git / github.com/dragonflydb/dragonfly

Affected ranges

Type
GIT
Repo
https://github.com/dragonflydb/dragonfly
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.40.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

i1.*
i1.33.3
i1.36.1
i1.36.2
i1.36.3
i1.39.10
i1.39.11
i1.39.2
i1.39.4
i1.39.6
i1.39.8
i1.39.9
v0.*
v0.1.0
v0.10.0
v0.11.0
v0.12.0
v0.13.0
v0.13.1
v0.14.0
v0.15.0
v0.16.0
v0.17.0
v0.2.0
v0.3.0
v0.3.0-alpha
v0.3.1
v0.4.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.9.0
v0.9.1
v1.*
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.11.0
v1.12.0
v1.13.0
v1.14.0
v1.15.0
v1.16.0
v1.17.0
v1.18.0
v1.19.0
v1.2.0
v1.2.1
v1.20.0
v1.21.0
v1.22.0
v1.23.0
v1.24.0
v1.26.0
v1.27.0
v1.28.0
v1.29.0
v1.3.0
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.39.0
v1.4.0
v1.5.0
v1.6.0
v1.7.0
v1.7.1
v1.8.0
v1.9.0
w0.*
w0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62357.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "211610076406049177367758484044134809698",
            "length": 287
        },
        "id": "CVE-2026-62357-3b5bafbf",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
        "target": {
            "file": "src/core/cms.cc",
            "function": "CMS::CMS"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "5322635667862774704304786385451744388",
                "66886196783674913294619631552708341386",
                "198048368828082106981029993325006176787",
                "240006315924978351772453842259916650506",
                "175523457867972427676949757412211360294",
                "208091916101434163357341777078200311244"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-62357-5b3a11ff",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
        "target": {
            "file": "src/server/cms_family_test.cc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "130585936608604658303845166766116616892",
                "107885826254918782674890319872812989855",
                "143323120089058282586446172549854694237",
                "215020614655049150903180848810109972302"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-62357-6859d390",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
        "target": {
            "file": "src/server/rdb_load.cc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "326546988665989418964483679692296212787",
                "261294368370366211537486739996430458843",
                "54577035639197598498529811661805438661",
                "226262520547116664413642351007982759195",
                "82003264845782041763169129325436076432",
                "22908802087225016360846923035840620791",
                "249870577877748641218662543289235468688",
                "204528849240036080322805419595189127645",
                "236289811163365274349986478566039298228",
                "181015966572041289815382278999968256739",
                "299842543910091958129801951071722602752",
                "109471931642327954755727622604190447627",
                "252721095131456832356784285004118551663",
                "180483997014715746735996915159310832760",
                "226507359704114734751633079389011690922",
                "172608647554937876326735470700110418312"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-62357-6d623a05",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
        "target": {
            "file": "src/core/cms.cc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "268523874514195481247651679642540955047",
            "length": 133
        },
        "id": "CVE-2026-62357-74803e9e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
        "target": {
            "file": "src/core/cms.cc",
            "function": "CMS::~CMS"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "166458192596899558720045250913960581656",
            "length": 875
        },
        "id": "CVE-2026-62357-7ce73c65",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
        "target": {
            "file": "src/server/cms_family.cc",
            "function": "CmdInitByProb"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "108142728200635670846621813511368675497",
            "length": 998
        },
        "id": "CVE-2026-62357-822e27c3",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
        "target": {
            "file": "src/server/rdb_load.cc",
            "function": "RdbLoaderBase::ReadCMS"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "126266558296851872821442021129732622758",
                "309387694038384607946984148821318057030",
                "18383488015668467856844079310516349067",
                "195143117881872716203820970696667162848",
                "11583402942871686552239329101928941686"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-62357-8f6c6fd4",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/e4ebd87e85c011f72aa646942ef87b8703d3443b",
        "target": {
            "file": "src/server/db_slice.cc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "95380582024133472853688761177186158628",
            "length": 554
        },
        "id": "CVE-2026-62357-af9ef26d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/e4ebd87e85c011f72aa646942ef87b8703d3443b",
        "target": {
            "file": "src/server/db_slice.cc",
            "function": "AccountObjectMemory"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "301254880437537105958376890331129291847",
            "length": 751
        },
        "id": "CVE-2026-62357-b57bca8f",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
        "target": {
            "file": "src/server/cms_family.cc",
            "function": "CmdInitByDim"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "16180070476676575682002681068948326393",
            "length": 469
        },
        "id": "CVE-2026-62357-d1d4c91e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
        "target": {
            "file": "src/server/cms_family.cc",
            "function": "OpInitByProb"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "182576966063876680064100708485032424839",
            "length": 1650
        },
        "id": "CVE-2026-62357-d8021478",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
        "target": {
            "file": "src/server/topk_family.cc",
            "function": "TopkFamily::Reserve"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "148277050649825178915387525857206898407",
                "315436223152657796052384274298663642190",
                "135743326164093846698374518920218787069",
                "115447363404704727468888404907224893651",
                "136524342585533875305528799996635351461",
                "301611135868608418012681345338576202008",
                "160769278250656544163410210139617439912",
                "114289193372147066870793584892279924938",
                "322343239175857834490837910609154567452",
                "265784978133679873744335278281760551279",
                "314670208432417967780790740430318228557",
                "94505295605800288117724702057635664075",
                "48800843734390190077056865420641090106",
                "285921644338427037669958508481122937928",
                "191821388118054824332906545998702857912",
                "31245848844017292033289131401794918008",
                "83532725745478892386170748535994092904",
                "70968742688256471497972680291448361598",
                "302474930139706989704278046162807116661",
                "128261498888540707934566869093157962171",
                "92137815719616682395720206275223817185",
                "133375864684157095368624552481248038128",
                "231287147525687936074629205088962259729",
                "266964488576513742250662735561227632394",
                "194690155019045898659920869462698146137",
                "260101508465618993661690390557611114997",
                "100115118831813957715884167788758966071",
                "320832550988267212069920672357553571996",
                "339024042150671829238856488417419542774",
                "273366004019004435328688306775340605115",
                "111036665116251170690313608029839477610",
                "194569545872976801223483719096244946897"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-62357-e2b14714",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
        "target": {
            "file": "src/server/cms_family.cc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "237816498549518553439389218087208171782",
                "257287862434300888839049252140650834095",
                "148190579141667079587705847378621052081",
                "340145901237256693308061158817851349701",
                "180557762326646257468783137732033542896",
                "211850758799689948451466074768285394397"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-62357-f4b7777d",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3",
        "target": {
            "file": "src/server/topk_family.cc"
        }
    }
]
vanir_signatures_modified
"2026-09-12T08:08:20Z"