PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86227 valkey-io CVE debrief

A weakness was identified in valkey-io valkey up to 9.0.5/9.1.1, affecting the function kvstoreGetHashtable in src/kvstore.c, allowing for an out-of-bounds read via manipulation of the argument didx. This issue can be exploited remotely with high complexity and difficult exploitability. The exploit has been made public and could be used for attacks, requiring cluster mode and attacker-controlled dump.rdb at startup.

Vendor
valkey-io
Product
valkey
CVSS
LOW 1.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-06
Original CVE updated
2026-09-06
Advisory published
2026-09-06
Advisory updated
2026-09-06

Who should care

Defenders responsible for valkey-io valkey deployments should assess exposure and prioritize patch deployment for memory safety, considering high complexity and difficult exploitability. They should also verify cluster mode configurations, ensure proper access controls for dump.rdb, and monitor for potential DoS attacks at boot. Additionally, defenders should review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. This requires coordination with vulnerability management and security teams to ensure proper mitigation and minimize potential impacts on operations and assets. Defenders should also consider the potential for remote DoS at boot with high complexity and difficult exploitability, and memory safety concerns requiring patch deployment, as well as the need for verification of cluster mode configurations and access controls. This issue may impact operators who manage valkey-io valkey deployments, particularly those with cluster mode enabled, and requires their attention to prevent potential disruptions. Security teams should also review relevant monitoring, detection, and logs for exposed assets that need extra review to ensure timely detection and response to potential attacks. Overall, defenders should prioritize patch deployment and take proactive measures to minimize potential impacts on operations and assets. Defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Defenders should also check relevant monitoring, detection, and logs for exposed assets that need extra review, and track exceptions, retest remediated assets, and close the item only after evidence is documented. Defenders should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. This requires coordination with vulnerability management and security teams to ensure proper mitigation and minimize potential impacts on The

Why it matters

Defenders should prioritize patch deployment for CVE-2026-86227 due to potential memory safety concerns and remote DoS at boot, considering high complexity and difficult exploitability.

  • Potential for remote DoS at boot with high complexity and difficult exploitability.
  • Memory safety concerns requiring patch deployment.
  • Need for verification of cluster mode configurations and access controls.

Technical summary

The weakness in valkey-io valkey up to 9.0.5/9.1.1 affects the kvstoreGetHashtable function in src/kvstore.c, allowing for an out-of-bounds read via manipulation of the argument didx. This issue can be exploited remotely with high complexity and difficult exploitability, potentially leading to a DoS at boot. Defenders should prioritize patch deployment for memory safety, considering the attack complexity and potential for DoS at boot.

Defensive priority

Defenders should prioritize patch deployment for memory safety, considering the attack complexity and potential for DoS at boot.

Recommended defensive actions

  • Deploy the patch 4691888e7fab3df128f0bde5750c9fde2ae552fa to fix the issue.
  • Verify cluster mode configurations and ensure proper access controls for dump.rdb.
  • Monitor for potential DoS attacks at boot.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.

Evidence notes

The issue report was closed stating it 'is worth fixing for the sake of memory safety… but I don't think it meets our bar for a security disclosure.' The weakness was identified in valkey-io valkey up to 9.0.5/9.1.1, affecting the function kvstoreGetHashtable in src/kvstore.c. Defenders should verify cluster mode configurations, access controls for dump.rdb, and monitor for potential DoS attacks at boot.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86227 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86227

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86227 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86227

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.