Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade valkey-develUpgrade valkey | Mar 9, 2026 | Mar 2, 2026 |
| Alpine Linux | — | Upgrade valkey | Apr 1, 2026 | Feb 23, 2026 |
| Amazon_linux_2023 | — | Upgrade valkey-develUpgrade valkey-debuginfoUpgrade valkeyUpgrade valkey-debugsource | Mar 9, 2026 | Feb 23, 2026 |
| Debian | — | Upgrade valkeyUpgrade redis | May 18, 2026 | May 18, 2026 |
| Oracle_linux | — | Upgrade valkey-develUpgrade valkey | Feb 27, 2026 | Feb 23, 2026 |
| Redhat_linux | — | Upgrade valkey-debugsourceUpgrade valkey-debuginfoUpgrade valkeyUpgrade valkey-devel | Feb 27, 2026 | Feb 23, 2026 |
| Rocky_linux | — | Upgrade valkey-debuginfoUpgrade valkey-debugsourceUpgrade valkeyUpgrade valkey-devel | Mar 2, 2026 | Feb 28, 2026 |
| Ubuntu | — | Upgrade valkey-server | Mar 19, 2026 | Feb 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub