PT-2026-37085 · Redis+2 · Redis-Server+3

·

CVE-2026-23479

·

Published

2026-05-05

·

Updated

2026-08-26

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions redis-server versions 7.2.0 through 8.6.3
Description An authenticated attacker can trigger a use-after-free condition in the unblock client flow when a blocked client is evicted. This occurs because the system does not properly handle an error return from the processCommandAndResetClient() function when re-executing a blocked command. This flaw can be exploited to execute arbitrary OS commands on the server. The exploitation chain involves using a Lua script to leak a heap pointer, grooming client memory, and overwriting a function pointer in the Global Offset Table to redirect a standard string function to system(). This issue was present in all stable branches for over two years and is particularly critical for default deployments that lack passwords or use overly permissive roles.
Recommendations Update redis-server to version 7.2.14 or later. Update redis-server to version 7.4.9 or later. Update redis-server to version 8.2.6 or later. Update redis-server to version 8.4.3 or later. Update redis-server to version 8.6.3 or later. As a temporary mitigation, disable Lua scripting if it is not required to break the exploit chain. Restrict Redis access to trusted networks and avoid exposing the service directly to the internet. Tighten Access Control Lists (ACLs) to ensure no single role possesses both u/admin and u/scripting permissions simultaneously.

Exploit

Fix

RCE

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:25216
ALSA-2026:25219
ALSA-2026:25925
AZL-86093
BDU:2026-06444
BIT-KEYDB-2026-23479
BIT-REDIS-2026-23479
BIT-VALKEY-2026-23479
CVE-2026-23479
GHSA-93M2-935M-8RJ3
OESA-2026-2237
OPENSUSE-SU-2026:10711-1
OPENSUSE-SU-2026:10719-1
OPENSUSE-SU-2026:20776-1
OPENSUSE-SU-2026:21612-1
RHSA-2026:14316
RHSA-2026:25216
RHSA-2026:25219
RHSA-2026:25925
RHSA-2026:26306
RHSA-2026:26540
RHSA-2026:7662
SUSE-SU-2026:1949-1
SUSE-SU-2026:1950-1
SUSE-SU-2026:2099-1
SUSE-SU-2026:21814-1

Affected Products

Red Os
Redis
Rocky Linux
Redis-Server