VYPR

redis-poc

by Flowring

CVEs (1)

  • CVE-2026-66373HigJul 25, 2026
    risk 0.42cvss 7.5epss 0.01

    Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER…