CVE-2026-63639
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.
CSIRTS triage
- What
- Valkey contains a use-after-free vulnerability in stream deserialization that allows remote code execution.
- Who is affected
- Valkey deployments accepting stream data from untrusted sources or via exposed network interfaces.
- Urgency
- Critical severity (CVSS 8.8) and not yet exploited; immediate patching is essential before potential weaponization.
- Action
- Apply the latest Valkey security patch addressing use-after-free in stream deserialization code.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-63639
Get an email if CVE-2026-63639 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.89% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-63639)