PT-2026-82754 · Redis+1 · Redis+1

CVE-2026-81934

·

Published

2026-08-27

·

Updated

2026-09-08

CVSS v4.0

7.5

High

VectorAV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Redis versions prior to 8.2.9 Redis versions prior to 8.4.6 Redis versions prior to 8.6.6 Redis versions prior to 8.8.2 Redis versions prior to 8.10.1
Description A use-after-free issue exists in the tlsProcessPendingData() function, which manages the TLS pending-data list when the server is configured with TLS support. A remote, unauthenticated attacker can trigger memory corruption over TLS to execute arbitrary commands with the privileges of the Redis server. Non-TLS deployments are not impacted.
Recommendations Update to version 8.2.9 Update to version 8.4.6 Update to version 8.6.6 Update to version 8.8.2 Update to version 8.10.1

Exploit

Fix

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:64823
ALSA-2026:64824
AZL-98240
CVE-2026-81934

Affected Products

Redis
Rocky Linux