---
title: "Thinkst Canary Fixes Redis DoS Flaw in CVE-2026-85220"
description: "Thinkst Applied Research patched CVE-2026-85220, a Redis service DoS issue in Thinkst Canary honeypots. Update now, or disable Redis as a workaround."
canonical_url: "https://liners.com/news/thinkst-canary-cve-2026-85220-redis-dos-fix"
markdown_url: "https://liners.com/news/thinkst-canary-cve-2026-85220-redis-dos-fix.md"
type: "article"
language: "en"
published_at: "2026-09-22T09:59:31.778Z"
updated_at: "2026-09-22T09:59:35.598Z"
---

# Thinkst Canary Fixes Redis DoS Flaw in CVE-2026-85220

Thinkst Applied Research patched CVE-2026-85220, a Redis service DoS issue in Thinkst Canary honeypots. Update now, or disable Redis as a workaround.

## Breadcrumbs

- [News](/news)
- [Thinkst Canary Fixes Redis DoS Flaw in CVE-2026-85220](/news/thinkst-canary-cve-2026-85220-redis-dos-fix)

## Content

## In Short
- Thinkst Applied Research disclosed CVE-2026-85220 on September 21, 2026.
- The bug lets an unauthenticated attacker remotely cause a denial of service in a Thinkst Canary honeypot when its Redis service is enabled.
- Thinkst says it has fixed the issue across supported platforms, including a patched Docker image.

## What Happened
CVE-2026-85220 affects the Redis service in [Thinkst Canary](/thinkst-canary), a honeypot device used to detect intruders by acting like a decoy system. Thinkst said an attacker does not need to log in to trigger the issue, which means it can be exploited “unauthenticated.”

The impact is a denial of service, which means the honeypot can be knocked offline or made unstable, reducing its ability to alert defenders. The issue is only reachable when the Redis service is enabled. Redis is an in-memory database often used as a fast cache, Thinkst uses it here as a service component.

The weakness maps to CWE-770, “allocation of resources without limits or throttling.” In simple terms, the service can be pushed to consume too many resources because there are not enough safeguards to slow requests down.

Thinkst rated the vulnerability as low severity, with a CVSS 3.1 score of 3.7. The advisory credits Teddy Thobane (rootkiTed) for finding the issue.

## Why It Matters
Honeypots are security tools, but they still run real services and can become targets themselves. A DoS against a Canary might not expose data, but it can blind a detection setup at the exact time defenders want visibility.

For teams in Africa running small security operations, this is also a reliability issue. If a honeypot is hosted in a branch office or remote site, recovery might require hands-on support.

Thinkst says updates are already distributing for customers with automatic updates enabled. If updates are off, customers should update their Canaries. If patching is not possible immediately, the simplest workaround is to disable the Redis service, because Thinkst says the Canary is not affected when Redis is disabled.

## Sources and products

- [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-85220)
- [Thinkst Canary](/thinkst-canary)

## Related pages

- [Policy & Regulation](/news)

## Access and citation

- [Canonical HTML page](https://liners.com/news/thinkst-canary-cve-2026-85220-redis-dos-fix)
- [Markdown route index](/sitemap.md)
- [Agent access guide](/llms.txt)
