Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade redis | Aug 9, 2026 | Aug 9, 2026 |
| Redhat_linux | — | Upgrade redis-develUpgrade redisUpgrade valkeyUpgrade valkey-debuginfoUpgrade redis-debugsourceUpgrade redis-debuginfoUpgrade valkey-develUpgrade redis-docUpgrade valkey-debugsource | Aug 17, 2026 | Jul 25, 2026 |
| Redislabs Redis | — | Upgrade RedisLabs Redis to version 8.8.0 | Aug 12, 2026 | Jul 25, 2026 |
| Rocky_linux | — | Upgrade redisUpgrade redis-debuginfoUpgrade redis-develUpgrade valkey-develUpgrade redis-debugsourceUpgrade valkey-debuginfoUpgrade valkeyUpgrade valkey-debugsource | Sep 10, 2026 | Sep 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub