CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Redis security advisory (AV26-859)

unknown
Serial Number: AV26-859 Date: August 28, 2026 As of August 27, 2026, Redis is affected by a vulnerability in the following product: Redis 8.0 All except 8.10.1 All except 8.2.9 All except 8.4.6 All except 8.6.6 All except 8.8.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Fix use-after-free in tlsProcessPendingData() pending-list iteration GitHub Releases

CSIRTS triage

vendor: Redisproduct: RedisMemory corruptionaffected: 8.0 branch: before 8.10.1; before 8.2.9; before 8.4.6; before 8.6.6; before 8.8.2
What
Use-after-free vulnerability in tlsProcessPendingData() pending-list iteration.
Who is affected
Redis 8.0 series installations running unpatched versions across multiple minor version branches.
Urgency
High; use-after-free can cause denial of service or memory corruption leading to potential code execution.
Action
Update to patched versions: 8.10.1, 8.2.9, 8.4.6, 8.6.6, or 8.8.2 depending on your Redis 8.x branch.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Redis

Get an email when a new Redis advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-28
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/redis-security-advisory-av26-859

More from Canadian Centre for Cyber Security