Redis saw three RCEs in August 2026, one bypassing an earlier fix
Redis disclosed three remote code execution flaws in August 2026. The main one is a use-after-free in tlsProcessPendingData() (QVD-2026-58458, CVSS cut from 9.8 to 7.5), fixed in 8.10.1, 8.8.2, 8.6.6, 8.4.6, 8.2.9, 7.4.11, 7.2.16 and 6.2.24. Another flaw bypassed the patch for CVE-2026-23479.
- QVD-2026-58458 is a use-after-free in tlsProcessPendingData() with TLS builds
- CVSS cut from 9.8 to 7.5 due to auth and runtime requirements
- Fixes span branches 6.2.24 through 8.10.1
- Bypass of CVE-2026-23479 uses XGROUP, EVAL and RESTORE
Read next
Security