PatchSiren

valkey-io CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW valkey-io CVE published 2026-09-06

CVE-2026-86227

A weakness was identified in valkey-io valkey up to 9.0.5/9.1.1, affecting the function kvstoreGetHashtable in src/kvstore.c, allowing for an out-of-bounds read via manipulation of the argument didx. This issue can be exploited remotely with high complexity and difficult exploitability. The exploit has been made public and could be used for attacks, requiring cluster mode and attacker-controlled dump.rdb at startup.

LOW valkey-io CVE published 2026-08-31

CVE-2026-82677

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T10:16:50.780Z and has not been modified since then. A double free vulnerability was determined in valkey-io valkey 9.1.0, specifically in the moduleTimerHandler function of src/module.c. The attack can be initiated remotely. This vulnerability has been publicly disclosed and may be utilized by at [truncated]

HIGH valkey-io CVE published 2026-08-18

CVE-2026-63639

CVE-2026-63639 is a high-severity vulnerability in Valkey, a distributed key-value database. The vulnerability exists in the RESTORE command, which can accept a malformed RDB stream payload, potentially leading to remote code execution. This issue has been fixed in Valkey versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1. Defenders should assess exposure and prioritize patching to prevent potential remote [truncated]

HIGH valkey-io CVE published 2026-08-18

CVE-2026-56684

A use-after-free vulnerability exists in Valkey, a distributed key-value database, prior to versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1. The tlsProcessPendingData function iterates over pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node. This can crash the server or potentially allow remote code execution when TLS is enabled.

HIGH valkey-io CVE published 2026-02-23

CVE-2026-27623

CVE-2026-27623 is a HIGH severity vulnerability in Valkey, a distributed key-value database. A malicious actor with network access can cause the system to abort by triggering an assertion. The issue arises from the system's improper handling of empty requests, allowing an attacker to send a request that the server incorrectly identifies as breaking server-side invariants, resulting in the server shutting [truncated]

HIGH valkey-io CVE published 2026-02-23

CVE-2025-67733

CVE-2025-67733 is a high-severity vulnerability in the Valkey distributed key-value database. Malicious users can inject arbitrary information into the response stream for a given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for Lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the [truncated]