CVE-2026-63639 - Valkey: UAF in stream deserialization may lead to remote code execution
Brief
CVE ID : CVE-2026-63639
Published : Aug. 18, 2026, 2:23 p. m.
- 44 minutes ago
Description : Valkey is a distributed key-value database. Prior to 7.
- 14, 8.
- 10, 8.
- 9, 9.
- 5, and 9.
- 1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.
- 14, 8.
- 10, 8.
- 9, 9.
- 5, and 9.
- 1.
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
