Critical severity9.8NVD Advisory· Published Aug 27, 2026
CVE-2026-81934
CVE-2026-81934
Description
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834nvd
- github.com/v12-security/pocs/tree/main/redis/server_sslnvd
- raw.githubusercontent.com/redis/redis/8.10/00-RELEASENOTESnvd
- raw.githubusercontent.com/redis/redis/8.2/00-RELEASENOTESnvd
- raw.githubusercontent.com/redis/redis/8.4/00-RELEASENOTESnvd
- raw.githubusercontent.com/redis/redis/8.6/00-RELEASENOTESnvd
- raw.githubusercontent.com/redis/redis/8.8/00-RELEASENOTESnvd
News mentions
0No linked articles in our index yet.