# TC-2026-01: Thinkst Canary Denial-of-Service in the Redis service Thinkst ID: TC-2026-01 CVE: CVE-2026-85220 CWE: CWE-770 First published: 2026-09-21 Version: 1.0 CVSS v3.1 Overall Score: 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C) # Summary A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. The Canary is NOT affected if the Redis service is disabled. Thinkst has addressed this issue on all supported platforms. New update files to address this issue are available on all platforms except Docker. For Docker customers, a new Docker image has been published which includes the patch. Customers with automatic updates enabled already have updates in distribution. If automatic updates are disabled, customers are advised to update their Canaries. Workarounds are available for customers unable to update at this time. # Affected products Thinkst Canary honeypots across these platforms: * AWS EC2 * Docker * GCP * Hardware * Microsoft Azure * Microsoft Hyper-V * Nutanix * OCI * OpenStack * Tailscale * VMware ESXi # Vulnerable Products Canary is available across multiple platforms, each with its own version number. The table below shows the first affected and patched versions for all Canary platforms. Platform | First Vulnerable Canary Release | First Fixed Canary Release ------------------+---------------------------------+---------------------------- AWS EC2 | 2.0.2 | 5.3.2 Docker | 3.7.1 | 5.7.2 GCP | 2.2.3 | 5.4.2 Hardware | 1.0 | 5.1.2 Microsoft Azure | 2.2.9 | 5.6.4 Microsoft Hyper-V | 2.3.2 | 5.5.2 Nutanix | 4.9.0 | 5.9.2 OCI | 3.11.10 | 5.11.2 OpenStack | 3.8.9 | 5.8.2 Tailscale | 2.2.1 | 5.3.2 VMware ESXi | 2.0.2 | 5.2.2 # Impact Exploitation of this vulnerability leads to the Canary becoming unresponsive during the attack. It will reboot itself within several minutes after the attack has commenced, so an attacker must continue the attack. # Customer actions Customers who have automatic updates enabled do not need to do anything as we are pushing out updates to live devices. Customers can confirm their Canary status by logging into their Console, clicking on the Canary, and confirming that the devices show as up-to-date. Customers without automatic updates enabled will receive communication from us, and should manually update their Canaries by logging into their Consoles, and selecting "Updates" under the "?" menu on the top right. They will see a list of outdated devices, and can click "Update" to update them. We do not push updates to running Docker Canaries, instead we publish new container images. Customers with Docker Canaries must update the image tag in their configurations. Use the “5.7.2” tag to fetch a fixed Docker image and redeploy your containers to launch the fresh image. #Workarounds 1. Disable the Redis service # Exploitation Thinkst is not aware of any public announcements or malicious use of this vulnerability. # Credit We thank security researcher Teddy Thobane (rootkiTed) for the report. # Timeline 2026-09-02: Vulnerability report received 2026-09-02: Report acknowledged and confirmed 2025-09-16: Patch developed 2026-09-18: Patch tested 2026-09-19: Commenced patch deployment to Canaries 2026-09-21: Security advisory published # Advisory Revision History Version | Description | Date --------+------------------------+------------ 1.0 | Initial public release | 2026-09-21