CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-56684

highCVSS 7.5covered by 2 sourcesfirst seen 2026-08-11
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-free that can crash the server or potentially allow remote code execution when TLS is enabled. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.

CSIRTS triage

What
Valkey contains a use-after-free vulnerability in TLS pending-data processing that can be triggered remotely to execute code.
Who is affected
Valkey deployments accepting TLS connections with pending data buffers.
Urgency
High severity (CVSS 7.5) and not yet exploited; immediate patching is recommended before external exposure.
Action
Apply the latest Valkey security patch that fixes use-after-free in TLS pending-data handling.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-56684

Get an email if CVE-2026-56684 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-56684

CVE.org record

Embed the live status

CVE-2026-56684 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-56684 status](https://www.csirts.com/badge/CVE-2026-56684)](https://www.csirts.com/cve/CVE-2026-56684)