PT-2026-64451 · Redis · Redis

CVE-2026-66373

·

Published

2026-07-24

·

Updated

2026-09-08

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Redis versions prior to 8.8.0
Description A double free error occurs when an authenticated attacker executes the RESTORE command. This happens when a RESTORE payload references the same NACK (pending entry) across multiple consumers, and both consumers are subsequently deleted using the XGROUP DELCONSUMER function. This flaw can allow a remote attacker to execute arbitrary code.
Recommendations Update to version 8.8.0 or later.

Exploit

Fix

RCE

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:64796
ALSA-2026:64807
ALSA-2026:64823
ALSA-2026:64824
AZL-93408
BDU:2026-10490
CVE-2026-66373
OESA-2026-3298
RHSA-2026:43236
SUSE-SU-2026:3636-1
SUSE-SU-2026:3637-1
SUSE-SU-2026:3638-1
SUSE-SU-2026:3639-1

Affected Products

Redis