High severity7.5OSV Advisory· Published Jul 25, 2026· Updated Sep 9, 2026
CVE-2026-66373
CVE-2026-66373
Description
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- osv-coords5 versionspkg:rpm/almalinux/redispkg:rpm/almalinux/redis-develpkg:rpm/almalinux/redis-docpkg:rpm/almalinux/valkeypkg:rpm/almalinux/valkey-devel
< 6.2.24-1.module_el8.10.0+4271+7f8f19af+ 4 more
- (no CPE)range: < 6.2.24-1.module_el8.10.0+4271+7f8f19af
- (no CPE)range: < 6.2.24-1.module_el8.10.0+4271+7f8f19af
- (no CPE)range: < 6.2.24-1.module_el8.10.0+4271+7f8f19af
- (no CPE)range: < 8.0.11-1.el10_2
- (no CPE)range: < 8.0.11-1.el10_2
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.