RubySec

Providing security resources for the Ruby community

GHSA-m252-9cgf-vx2w (dalli): With a namespace, a retried request reads or writes a different key

With a namespace, a retried request reads or writes a different key

Published: October 05, 2026

SECURITY IDENTIFIERS

GEM

dalli

UNAFFECTED VERSIONS

< 4.1.0

PATCHED VERSIONS

~> 4.3.7 ~> 5.0.10 ~> 5.1.4 >= 5.2.2

DESCRIPTION

When a client is configured with a namespace, a request that hits a transient network error (a timeout, or a connection closed by memcached or a proxy, such as stale connections after a memcached restart) was retried with the namespace applied a second time, so app:x became app:app:x. A retried read could return a different key's value, and a retried write could overwrite a different key. Where cache keys include user input, a user who can choose a key of the form app:&lt;something&gt; can arrange for another user's retried read to return attacker-chosen data.

Affected: every single-key operation since 5.0.3, single-server get_multi since 5.1.0, and get_with_metadata and fetch_with_lock since 4.1.0. Clients without a namespace are not affected, and 3.2.x is not affected.

Workarounds

Don't configure a namespace; prefix keys in application code instead.

RELATED