Routing tokens can inject meta protocol flags, and failed requests can retry forever
Published: October 05, 2026
SECURITY IDENTIFIERS
- GHSA: GHSA-4qp6-2jcr-596v
- Vendor Advisory: https://github.com/petergoldstein/dalli/security/advisories/GHSA-4qp6-2jcr-596v
GEM
PATCHED VERSIONS
~> 3.2.12
~> 4.3.6
~> 5.0.9
~> 5.1.3
>= 5.2.1
DESCRIPTION
p_tokenandl_tokenwere checked only for CR, LF and NUL. A token containing spaces added arbitrary meta flags to the command: for example changing an item's TTL on a read, creating stub items on a miss, turning a delete into a stale tombstone, choosingincr's initial value, or reading a different key. Affects 5.1.0 and later.- Failed requests were retried without a limit. Each retry reconnected
successfully, which reset the failure count, so
socket_max_failureswas never reached and requests to a server that accepts connections but never replies (or drops the connection on a request) hung forever. Affects all versions. - Errors raised by application code inside a
get_multiblock (Errno::*,Timeout::Error) were treated as socket errors and retried the wholeget_multi, causing duplicate yields, swallowed exceptions, or an endless loop. Affects 4.x and 5.x.
Workarounds
Don't pass untrusted input as a routing token.
RELATED
- https://github.com/petergoldstein/dalli/security/advisories/GHSA-4qp6-2jcr-596v
- https://github.com/petergoldstein/dalli/commit/f8f7a21
- https://rubygems.org/gems/dalli/versions/5.2.1
- https://github.com/petergoldstein/dalli/releases/tag/v5.2.1
- https://rubygems.org/gems/dalli/versions/5.1.3
- https://github.com/petergoldstein/dalli/releases/tag/v5.1.3
- https://rubygems.org/gems/dalli/versions/5.0.9
- https://github.com/petergoldstein/dalli/releases/tag/v5.0.9
- https://rubygems.org/gems/dalli/versions/4.3.6
- https://github.com/petergoldstein/dalli/releases/tag/v4.3.6
- https://rubygems.org/gems/dalli/versions/3.2.12
- https://github.com/petergoldstein/dalli/releases/tag/v3.2.12
