VYPR

Valkey

by Valkey Io

Source repositories

CVEs (10)

  • CVE-2025-67733HigFeb 23, 2026
    risk 0.55cvss 8.5epss 0.01

    Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other…

  • CVE-2026-63639HigAug 18, 2026
    risk 0.50cvss 8.8epss 0.01

    Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a…

  • CVE-2026-27623HigFeb 23, 2026
    risk 0.49cvss 7.5epss 0.01

    Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can cause the system to abort by triggering an assertion. When processing incoming requests, the Valkey system does not properly…

  • CVE-2026-21863HigFeb 23, 2026
    risk 0.49cvss 7.5epss 0.01

    Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey…

  • CVE-2026-56684HigAug 18, 2026
    risk 0.42cvss 7.5epss 0.01

    Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and…

  • CVE-2026-85522MedSep 4, 2026
    risk 0.27cvss 5.3epss 0.01

    A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.c of the component Slot Migration. The manipulation of the argument job_name results in out-of-bounds read.…

  • CVE-2026-86227LowSep 6, 2026
    risk 0.13cvss 3.1epss 0.01

    A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bounds read. It is possible to initiate the attack remotely. The attack is…

  • CVE-2025-49112LowJun 2, 2025
    risk 0.13cvss 3.1epss 0.00

    setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.

  • CVE-2026-82677LowAug 31, 2026
    risk 0.09cvss 2.4epss 0.01

    A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly…

  • CVE-2026-82631LowAug 31, 2026
    risk 0.07cvss 2.2epss 0.01

    A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The manipulation results in use after free. The attack may be performed from…