← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 18, 2026 · 14:23via CVEFeed

CVE-2026-63639 - Valkey: UAF in stream deserialization may lead to remote code execution

Brief

CVE ID : CVE-2026-63639

Published : Aug. 18, 2026, 2:23 p. m.

  • 44 minutes ago

Description : Valkey is a distributed key-value database. Prior to 7.

  • 14, 8.
  • 10, 8.
  • 9, 9.
  • 5, and 9.
  • 1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.
  • 14, 8.
  • 10, 8.
  • 9, 9.
  • 5, and 9.
  • 1.

Severity: 0.0

  • NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed