RubySec

Providing security resources for the Ruby community

GHSA-4qp6-2jcr-596v (dalli): Routing tokens can inject meta protocol flags, and failed requests can retry forever

Routing tokens can inject meta protocol flags, and failed requests can retry forever

Published: October 05, 2026

SECURITY IDENTIFIERS

GEM

dalli

PATCHED VERSIONS

~> 3.2.12 ~> 4.3.6 ~> 5.0.9 ~> 5.1.3 >= 5.2.1

DESCRIPTION

  1. p_token and l_token were checked only for CR, LF and NUL. A token containing spaces added arbitrary meta flags to the command: for example changing an item's TTL on a read, creating stub items on a miss, turning a delete into a stale tombstone, choosing incr's initial value, or reading a different key. Affects 5.1.0 and later.
  2. Failed requests were retried without a limit. Each retry reconnected successfully, which reset the failure count, so socket_max_failures was never reached and requests to a server that accepts connections but never replies (or drops the connection on a request) hung forever. Affects all versions.
  3. Errors raised by application code inside a get_multi block (Errno::*, Timeout::Error) were treated as socket errors and retried the whole get_multi, causing duplicate yields, swallowed exceptions, or an endless loop. Affects 4.x and 5.x.

Workarounds

Don't pass untrusted input as a routing token.

RELATED