PT-2026-83717 · Valkey Io · Valkey

·

CVE-2026-82631

·

Published

2026-08-31

·

Updated

2026-09-01

CVSS v3.1

2.2

Low

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions valkey-io valkey version 9.1.0
Description A use after free flaw exists in the Blocked-on-keys Subsystem within the handleClientsBlockedOnKey() function located in the src/blocked.c file. This issue can be triggered remotely, although the attack complexity is high and exploitability is considered difficult.
Recommendations Apply patch b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b for version 9.1.0.

Exploit

Fix

Buffer Overflow

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98439
CVE-2026-82631

Affected Products

Valkey