VDB
CVE-2026-63639
CVE-2026-63639
PUBLISHED
CVSS 8.8 HIGH
Reported by GitHub_M · Published August 18, 2026
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.
Risk Scores
CVSS 3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| valkey-io | valkey | < 7.2.14, >= 8.0.0, < 8.0.10, >= 8.1.0, < 8.1.9 |
| valkey-io | valkey | < 7.2.14, >= 8.0.0, < 8.0.10, >= 8.1.0, < 8.1.9 |
Timeline
- Jul 22, 2026 CVE Published
- Aug 22, 2026 Security Advisory
References
- https://github.com/valkey-io/valkey/security/advisories/GHSA-mvcj-73cw-22m4 x_refsource_CONFIRM
- https://github.com/valkey-io/valkey/pull/4073 x_refsource_MISC
- https://github.com/valkey-io/valkey/commit/06bc7768fe609f2054e69ccedefe7628f5675da9 x_refsource_MISC
- https://github.com/valkey-io/valkey/commit/509cb3c74e8cbc9c0498ebe8b6c93dcd605e7271 x_refsource_MISC
- https://github.com/valkey-io/valkey/commit/98465eaffe3f95524a5046318bfbc4bdb9798291 x_refsource_MISC
- https://github.com/valkey-io/valkey/commit/e95911d4d65be8789fa3705f44d7ed1e65378445 x_refsource_MISC
- https://github.com/valkey-io/valkey/commit/f8d2027e8d4df790ac04974bf606408c8ea62778 x_refsource_MISC
- https://github.com/valkey-io/valkey/releases/tag/7.2.14 x_refsource_MISC
- https://github.com/valkey-io/valkey/releases/tag/8.0.10 x_refsource_MISC
- https://github.com/valkey-io/valkey/releases/tag/8.1.9 x_refsource_MISC
- https://github.com/valkey-io/valkey/releases/tag/9.0.5 x_refsource_MISC
- https://github.com/valkey-io/valkey/releases/tag/9.1.1 x_refsource_MISC