Redis security advisory (AV26-859)
Serial Number: AV26-859 Date: August 28, 2026 As of August 27, 2026, Redis is affected by a vulnerability in the following product: Redis 8.0 All except 8.10.1 All except 8.2.9 All except 8.4.6 All except 8.6.6 All except 8.8.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Fix use-after-free in tlsProcessPendingData() pending-list iteration GitHub Releases
CSIRTS triage
- What
- Use-after-free vulnerability in tlsProcessPendingData() pending-list iteration.
- Who is affected
- Redis 8.0 series installations running unpatched versions across multiple minor version branches.
- Urgency
- High; use-after-free can cause denial of service or memory corruption leading to potential code execution.
- Action
- Update to patched versions: 8.10.1, 8.2.9, 8.4.6, 8.6.6, or 8.8.2 depending on your Redis 8.x branch.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Redis
Get an email when a new Redis advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/redis-security-advisory-av26-859
More from Canadian Centre for Cyber Security
- unknownCisco security advisory (AV26-921)2026-09-14
- unknownAndroid security advisory – September 2026 monthly rollup (AV26-920)2026-09-14
- unknownSamsung mobile security advisory (AV26-919)2026-09-14
- unknownMongoDB security advisory (AV26-918)2026-09-14
- criticalGitLab security advisory (AV26-917)2026-09-11