CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-63639

highCVSS 8.8covered by 2 sourcesfirst seen 2026-08-11
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.

CSIRTS triage

What
Valkey contains a use-after-free vulnerability in stream deserialization that allows remote code execution.
Who is affected
Valkey deployments accepting stream data from untrusted sources or via exposed network interfaces.
Urgency
Critical severity (CVSS 8.8) and not yet exploited; immediate patching is essential before potential weaponization.
Action
Apply the latest Valkey security patch addressing use-after-free in stream deserialization code.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-63639

Get an email if CVE-2026-63639 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-63639

CVE.org record

Embed the live status

CVE-2026-63639 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-63639 status](https://www.csirts.com/badge/CVE-2026-63639)](https://www.csirts.com/cve/CVE-2026-63639)