CVE-2026-85220: CWE-770 Allocation of resources without limits or throttling in Thinkst Applied Research Canary
CVE-2026-85220 is a low-severity vulnerability in the Thinkst Applied Research Canary honeypot's Redis service that allows unauthenticated remote attackers to cause a denial-of-service (DoS) condition. The vulnerability only affects Canaries with the Redis service enabled. Thinkst has released patches for all supported platforms and a new Docker image containing the fix. Automatic updates distribute the patch to customers with that feature enabled. Workarounds exist for those unable to update immediately.
AI Analysis
Technical Summary
This vulnerability (CWE-770) involves the allocation of resources without limits or throttling in the Redis service component of the Thinkst Canary honeypot. An unauthenticated remote attacker can exploit this flaw to execute a denial-of-service attack against the honeypot, causing service disruption. The issue is only exploitable if the Redis service is enabled; disabling Redis mitigates the vulnerability. Thinkst Applied Research has addressed the issue by releasing updates and a patched Docker image. Customers with automatic updates enabled have already received the fix, while others are advised to update manually. Workarounds are available for those who cannot update immediately.
Potential Impact
The vulnerability allows an unauthenticated remote attacker to cause a denial-of-service condition against the Canary honeypot by exploiting uncontrolled resource allocation in the Redis service. There is no impact on confidentiality or integrity, only availability is affected. The risk is limited to deployments with Redis enabled. No known exploits are reported in the wild.
Mitigation Recommendations
Thinkst Applied Research has provided official patches for all supported platforms and a new Docker image with the fix. Customers with automatic updates enabled have already received the patch. Those with automatic updates disabled should manually update their Canary devices. Disabling the Redis service entirely also mitigates the vulnerability. Workarounds are available for customers unable to update immediately. Users should follow vendor guidance to apply updates or disable Redis to prevent exploitation.
CVE-2026-85220: CWE-770 Allocation of resources without limits or throttling in Thinkst Applied Research Canary
Description
CVE-2026-85220 is a low-severity vulnerability in the Thinkst Applied Research Canary honeypot's Redis service that allows unauthenticated remote attackers to cause a denial-of-service (DoS) condition. The vulnerability only affects Canaries with the Redis service enabled. Thinkst has released patches for all supported platforms and a new Docker image containing the fix. Automatic updates distribute the patch to customers with that feature enabled. Workarounds exist for those unable to update immediately.
CVSS v3.1
Score 3.7low
Affected software
Thinkst Applied Research
Canary
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-770) involves the allocation of resources without limits or throttling in the Redis service component of the Thinkst Canary honeypot. An unauthenticated remote attacker can exploit this flaw to execute a denial-of-service attack against the honeypot, causing service disruption. The issue is only exploitable if the Redis service is enabled; disabling Redis mitigates the vulnerability. Thinkst Applied Research has addressed the issue by releasing updates and a patched Docker image. Customers with automatic updates enabled have already received the fix, while others are advised to update manually. Workarounds are available for those who cannot update immediately.
Potential Impact
The vulnerability allows an unauthenticated remote attacker to cause a denial-of-service condition against the Canary honeypot by exploiting uncontrolled resource allocation in the Redis service. There is no impact on confidentiality or integrity, only availability is affected. The risk is limited to deployments with Redis enabled. No known exploits are reported in the wild.
Mitigation Recommendations
Thinkst Applied Research has provided official patches for all supported platforms and a new Docker image with the fix. Customers with automatic updates enabled have already received the patch. Those with automatic updates disabled should manually update their Canary devices. Disabling the Redis service entirely also mitigates the vulnerability. Workarounds are available for customers unable to update immediately. Users should follow vendor guidance to apply updates or disable Redis to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- ThinkstAppliedResearch
- Date Reserved
- 2026-09-03T14:08:21.464Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab146f455bf5e2cf50fa1ea
Added to database: 09/21/2026, 15:02:12 UTC
Last enriched: 09/21/2026, 15:16:31 UTC
Last updated: 09/21/2026, 15:55:45 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.