Skip to content

With a namespace, a retried request reads or writes a different key

High
petergoldstein published GHSA-m252-9cgf-vx2w Oct 6, 2026

Package

bundler dalli (rubygems)

Affected versions

>= 4.1.0, < 4.3.7
>= 5.0.0, < 5.0.10
>= 5.1.0, < 5.1.4
>= 5.2.0, < 5.2.2

Patched versions

4.3.7
5.0.10
5.1.4
5.2.2

Description

Summary

When a client is configured with a namespace, a request that hits a transient network error (a timeout, or a connection that memcached or a proxy closed, such as stale connections after a memcached restart) is retried with the namespace applied a second time. Client#perform replaces its key argument with the validated, namespaced key and then uses retry, which re-runs the method with the already-namespaced key, so app:x becomes app:app:x.

Impact

  • A read returns the value of a different key: get('x') returned the value stored under app:app:x. Where cache keys include user input, a user who can choose a key of the form app:<something> can arrange for another user's retried read to return attacker-chosen data, or read data meant for another key.
  • A write lands on a different key, overwriting it.

Affected

  • 5.0.3 and later: every single-key operation (get, set, add, replace, delete, incr, decr, touch, gat, cas, append, prepend, ...).
  • 5.1.0 and later: single-server get_multi.
  • 4.1.0 and later, including all of 5.x: get_with_metadata and fetch_with_lock.
  • Clients without a namespace are not affected. 3.2.x is not affected.

Fix

Every attempt now starts from the caller's key. Fixed in 5.2.2, 5.1.4, 5.0.10 and 4.3.7.

Severity

High

CVE ID

No known CVE

Weaknesses

Use of Incorrectly-Resolved Name or Reference

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere. Learn more on MITRE.