PatchSiren cyber security CVE debrief
CVE-2026-86227 valkey-io CVE debrief
A weakness was identified in valkey-io valkey up to 9.0.5/9.1.1, affecting the function kvstoreGetHashtable in src/kvstore.c, allowing for an out-of-bounds read via manipulation of the argument didx. This issue can be exploited remotely with high complexity and difficult exploitability. The exploit has been made public and could be used for attacks, requiring cluster mode and attacker-controlled dump.rdb at startup.
- Vendor
- valkey-io
- Product
- valkey
- CVSS
- LOW 1.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-06
- Original CVE updated
- 2026-09-06
- Advisory published
- 2026-09-06
- Advisory updated
- 2026-09-06
Who should care
Defenders responsible for valkey-io valkey deployments should assess exposure and prioritize patch deployment for memory safety, considering high complexity and difficult exploitability. They should also verify cluster mode configurations, ensure proper access controls for dump.rdb, and monitor for potential DoS attacks at boot. Additionally, defenders should review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. This requires coordination with vulnerability management and security teams to ensure proper mitigation and minimize potential impacts on operations and assets. Defenders should also consider the potential for remote DoS at boot with high complexity and difficult exploitability, and memory safety concerns requiring patch deployment, as well as the need for verification of cluster mode configurations and access controls. This issue may impact operators who manage valkey-io valkey deployments, particularly those with cluster mode enabled, and requires their attention to prevent potential disruptions. Security teams should also review relevant monitoring, detection, and logs for exposed assets that need extra review to ensure timely detection and response to potential attacks. Overall, defenders should prioritize patch deployment and take proactive measures to minimize potential impacts on operations and assets. Defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Defenders should also check relevant monitoring, detection, and logs for exposed assets that need extra review, and track exceptions, retest remediated assets, and close the item only after evidence is documented. Defenders should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. This requires coordination with vulnerability management and security teams to ensure proper mitigation and minimize potential impacts on The
Why it matters
Defenders should prioritize patch deployment for CVE-2026-86227 due to potential memory safety concerns and remote DoS at boot, considering high complexity and difficult exploitability.
- Potential for remote DoS at boot with high complexity and difficult exploitability.
- Memory safety concerns requiring patch deployment.
- Need for verification of cluster mode configurations and access controls.
Technical summary
The weakness in valkey-io valkey up to 9.0.5/9.1.1 affects the kvstoreGetHashtable function in src/kvstore.c, allowing for an out-of-bounds read via manipulation of the argument didx. This issue can be exploited remotely with high complexity and difficult exploitability, potentially leading to a DoS at boot. Defenders should prioritize patch deployment for memory safety, considering the attack complexity and potential for DoS at boot.
Defensive priority
Defenders should prioritize patch deployment for memory safety, considering the attack complexity and potential for DoS at boot.
Recommended defensive actions
- Deploy the patch 4691888e7fab3df128f0bde5750c9fde2ae552fa to fix the issue.
- Verify cluster mode configurations and ensure proper access controls for dump.rdb.
- Monitor for potential DoS attacks at boot.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
Evidence notes
The issue report was closed stating it 'is worth fixing for the sake of memory safety… but I don't think it meets our bar for a security disclosure.' The weakness was identified in valkey-io valkey up to 9.0.5/9.1.1, affecting the function kvstoreGetHashtable in src/kvstore.c. Defenders should verify cluster mode configurations, access controls for dump.rdb, and monitor for potential DoS attacks at boot.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86227 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86227
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86227 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86227
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/user-attachments/files/30195539/RDB.zip
-
Source reference
Unverified legacy reference
URL: https://github.com/valkey-io/valkey/
-
Source reference
Unverified legacy reference
URL: https://github.com/valkey-io/valkey/commit/4691888e7fab3df128f0bde5750c9fde2ae552fa
-
Source reference
Unverified legacy reference
URL: https://github.com/valkey-io/valkey/issues/4222
-
Source reference
Unverified legacy reference
URL: https://github.com/valkey-io/valkey/pull/4229
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-86227
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/897659
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/399380
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.