Threats Tagged 'cve-2026-63639'
View all threats tagged with 'cve-2026-63639'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-63639'
Click on any threat for detailed analysis and mitigation recommendations
0 Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also. Security Fix(es): * redis: Redis: Remote Code Execution via specially crafted RESTORE payload (CVE-2026-66373) * valkey: Valkey: Remote code execution via use-after-free in stream deserialization (CVE-2026-63639) * valkey: Valkey: Remote code execution via TLS pending-data processing use-after-free (CVE-2026-56684) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/17/2026, 12:17:24 UTC Added: 09/08/2026, 12:55:03 UTC |
Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also. Security Fix(es): * redis: Redis: Remote Code Execution via specially crafted RESTORE payload (CVE-2026-66373) * valkey: Valkey: Remote code execution via use-after-free in stream deserialization (CVE-2026-63639) * valkey: Valkey: Remote code execution via TLS pending-data processing use-after-free (CVE-2026-56684) Bug Fix(es) and Enhancement(s): * [Tracker] Rebase valkey to 8.0.10 (JIRA:RHEL-216776) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/08/2026, 05:14:42 UTC Added: 09/08/2026, 12:55:03 UTC |
0 CVE-2026-63639 is a high-severity use-after-free vulnerability in the valkey distributed key-value database. It affects the RESTORE command prior to versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1. The flaw arises when a malformed RDB stream payload assigns a single Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, leading to a use-after-free condition if one consumer is deleted while others still reference the shared NACK. This can potentially allow remote code execution. The issue is fixed in the specified patched versions. Join the discussion | CVE Database V5 | 08/18/2026, 14:23:52 UTC Added: 08/18/2026, 14:35:00 UTC |
Showing 1 to 3 of 3 results