CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Redis security advisory (AV26-748)

unknown
Serial number: AV26-748 Date: July 27, 2026 As of July 25, 2026, Redis is affected by a vulnerability in the following product: Redis Versions prior to 8.8.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Comparing 8.6.4...8.8.0 Reject corrupt stream RDB with shared NACK across consumers #15081 Releases · redis/redis · GitHub

CSIRTS triage

vendor: Redisproduct: RedisOtheraffected: Prior to 8.8.0
What
A vulnerability affects Redis that may lead to issues with corrupt stream RDB handling.
Who is affected
Users of Redis versions prior to 8.8.0.
Urgency
Remediation is necessary, but exploitation status is unclear.
Action
Upgrade to Redis version 8.8.0 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Redis

Get an email when a new Redis advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-07-27
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/redis-security-advisory-av26-748

More from Canadian Centre for Cyber Security