{"id":"CVE-2026-62357","summary":"DragonflyDB `CMS.INITBYDIM` integer overflow leads to a remote, attacker-controlled heap out-of-bounds write","details":"Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whose width times depth times sizeof(int64_t) overflows in src/core/cms.cc, allocating an undersized counter buffer while CMS.INCRBY and CMS.QUERY use the unbounded dimensions, which allows an unauthenticated remote client to corrupt or disclose adjacent heap memory and crash the server. This issue is fixed in version 1.40.0.","aliases":["GHSA-cmmv-h748-v93x"],"modified":"2026-09-12T08:08:20.503818Z","published":"2026-08-18T15:18:52.900Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62357.json"},"references":[{"type":"WEB","url":"https://github.com/dragonflydb/dragonfly/releases/tag/v1.40.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62357.json"},{"type":"ADVISORY","url":"https://github.com/dragonflydb/dragonfly/security/advisories/GHSA-cmmv-h748-v93x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62357"},{"type":"FIX","url":"https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3"},{"type":"FIX","url":"https://github.com/dragonflydb/dragonfly/pull/7647"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dragonflydb/dragonfly","events":[{"introduced":"0"},{"fixed":"c004623249fe2151dc5d64e21364fb9fb07c90d3"},{"fixed":"e4ebd87e85c011f72aa646942ef87b8703d3443b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.40.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["i1.39.11","i1.39.10","i1.39.9","i1.39.8","i1.39.6","i1.39.4","i1.39.2","v1.39.0","v1.38.0","v1.37.0","v1.36.0","i1.36.3","i1.36.2","v1.32.0","i1.36.1","v1.35.0","v1.34.0","i1.33.3","v1.33.0","v1.31.0","v1.30.0","v1.29.0","v1.28.0","v1.27.0","v1.26.0","v1.24.0","v1.23.0","v1.22.0","v1.21.0","v1.20.0","v1.19.0","v1.18.0","v1.17.0","v1.16.0","v1.15.0","w0.1","v1.14.0","v1.13.0","v1.12.0","v1.11.0","v1.9.0","v1.8.0","v1.7.1","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.0","v1.2.1","v1.2.0","v1.1.2","v1.1.1","v1.1.0","v1.0.0","v0.17.0","v0.16.0","v0.15.0","v0.14.0","v0.13.1","v0.13.0","v0.12.0","v0.11.0","v0.10.0","v0.9.1","v0.9.0","v0.8.0","v0.7.0","v0.6.0","v0.5.0","v0.4.0","v0.3.1","v0.3.0","v0.3.0-alpha","v0.2.0","v0.1.0"],"database_specific":{"vanir_signatures":[{"target":{"file":"src/core/cms.cc","function":"CMS::CMS"},"deprecated":false,"digest":{"function_hash":"211610076406049177367758484044134809698","length":287},"id":"CVE-2026-62357-3b5bafbf","signature_type":"Function","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3"},{"digest":{"line_hashes":["5322635667862774704304786385451744388","66886196783674913294619631552708341386","198048368828082106981029993325006176787","240006315924978351772453842259916650506","175523457867972427676949757412211360294","208091916101434163357341777078200311244"],"threshold":0.9},"id":"CVE-2026-62357-5b3a11ff","signature_type":"Line","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3","target":{"file":"src/server/cms_family_test.cc"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3","target":{"file":"src/server/rdb_load.cc"},"deprecated":false,"digest":{"line_hashes":["130585936608604658303845166766116616892","107885826254918782674890319872812989855","143323120089058282586446172549854694237","215020614655049150903180848810109972302"],"threshold":0.9},"id":"CVE-2026-62357-6859d390"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3","target":{"file":"src/core/cms.cc"},"deprecated":false,"digest":{"line_hashes":["326546988665989418964483679692296212787","261294368370366211537486739996430458843","54577035639197598498529811661805438661","226262520547116664413642351007982759195","82003264845782041763169129325436076432","22908802087225016360846923035840620791","249870577877748641218662543289235468688","204528849240036080322805419595189127645","236289811163365274349986478566039298228","181015966572041289815382278999968256739","299842543910091958129801951071722602752","109471931642327954755727622604190447627","252721095131456832356784285004118551663","180483997014715746735996915159310832760","226507359704114734751633079389011690922","172608647554937876326735470700110418312"],"threshold":0.9},"id":"CVE-2026-62357-6d623a05"},{"source":"https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3","target":{"file":"src/core/cms.cc","function":"CMS::~CMS"},"deprecated":false,"digest":{"length":133,"function_hash":"268523874514195481247651679642540955047"},"id":"CVE-2026-62357-74803e9e","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"166458192596899558720045250913960581656","length":875},"id":"CVE-2026-62357-7ce73c65","signature_type":"Function","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3","target":{"file":"src/server/cms_family.cc","function":"CmdInitByProb"}},{"deprecated":false,"digest":{"function_hash":"108142728200635670846621813511368675497","length":998},"id":"CVE-2026-62357-822e27c3","signature_type":"Function","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3","target":{"file":"src/server/rdb_load.cc","function":"RdbLoaderBase::ReadCMS"}},{"deprecated":false,"digest":{"line_hashes":["126266558296851872821442021129732622758","309387694038384607946984148821318057030","18383488015668467856844079310516349067","195143117881872716203820970696667162848","11583402942871686552239329101928941686"],"threshold":0.9},"id":"CVE-2026-62357-8f6c6fd4","signature_type":"Line","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/e4ebd87e85c011f72aa646942ef87b8703d3443b","target":{"file":"src/server/db_slice.cc"}},{"signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/e4ebd87e85c011f72aa646942ef87b8703d3443b","target":{"file":"src/server/db_slice.cc","function":"AccountObjectMemory"},"deprecated":false,"digest":{"length":554,"function_hash":"95380582024133472853688761177186158628"},"id":"CVE-2026-62357-af9ef26d","signature_type":"Function"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3","target":{"file":"src/server/cms_family.cc","function":"CmdInitByDim"},"deprecated":false,"digest":{"function_hash":"301254880437537105958376890331129291847","length":751},"id":"CVE-2026-62357-b57bca8f"},{"source":"https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3","target":{"file":"src/server/cms_family.cc","function":"OpInitByProb"},"deprecated":false,"digest":{"length":469,"function_hash":"16180070476676575682002681068948326393"},"id":"CVE-2026-62357-d1d4c91e","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"182576966063876680064100708485032424839","length":1650},"id":"CVE-2026-62357-d8021478","signature_type":"Function","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3","target":{"file":"src/server/topk_family.cc","function":"TopkFamily::Reserve"}},{"signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3","target":{"file":"src/server/cms_family.cc"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["148277050649825178915387525857206898407","315436223152657796052384274298663642190","135743326164093846698374518920218787069","115447363404704727468888404907224893651","136524342585533875305528799996635351461","301611135868608418012681345338576202008","160769278250656544163410210139617439912","114289193372147066870793584892279924938","322343239175857834490837910609154567452","265784978133679873744335278281760551279","314670208432417967780790740430318228557","94505295605800288117724702057635664075","48800843734390190077056865420641090106","285921644338427037669958508481122937928","191821388118054824332906545998702857912","31245848844017292033289131401794918008","83532725745478892386170748535994092904","70968742688256471497972680291448361598","302474930139706989704278046162807116661","128261498888540707934566869093157962171","92137815719616682395720206275223817185","133375864684157095368624552481248038128","231287147525687936074629205088962259729","266964488576513742250662735561227632394","194690155019045898659920869462698146137","260101508465618993661690390557611114997","100115118831813957715884167788758966071","320832550988267212069920672357553571996","339024042150671829238856488417419542774","273366004019004435328688306775340605115","111036665116251170690313608029839477610","194569545872976801223483719096244946897"]},"id":"CVE-2026-62357-e2b14714","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["237816498549518553439389218087208171782","257287862434300888839049252140650834095","148190579141667079587705847378621052081","340145901237256693308061158817851349701","180557762326646257468783137732033542896","211850758799689948451466074768285394397"],"threshold":0.9},"id":"CVE-2026-62357-f4b7777d","signature_type":"Line","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/c004623249fe2151dc5d64e21364fb9fb07c90d3","target":{"file":"src/server/topk_family.cc"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62357.json","vanir_signatures_modified":"2026-09-12T08:08:20Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"}]}