CVE-2026-23479
High · CVSS 8.8Redis (redis-server) — Use-After-Free (UAF) Remote Code Execution via unblock client flow
- CVSS
- 8.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-416, CWE-416
Description
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
Search profile — drives PoC discovery
Ranked PoCs (4) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 0
- ★ 0
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://github.com/redis/redis/releases/tag/8.6.3
- https://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3
- https://access.redhat.com/errata/RHSA-2026:25216
- https://access.redhat.com/errata/RHSA-2026:25219
- https://access.redhat.com/errata/RHSA-2026:25925
- https://access.redhat.com/errata/RHSA-2026:26306
- https://access.redhat.com/errata/RHSA-2026:26540
- https://access.redhat.com/security/cve/CVE-2026-23479
- https://bugzilla.redhat.com/show_bug.cgi?id=2466780
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23479.json
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:30:14.000Z