{"id":"CVE-2026-23479","title":"Redis is an in-memory data structure store","summary":"Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is e…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416","CWE-416"],"vendor":"redis","product":"redis","affected":["redis >= 7.2.0, < 8.6.3"],"patched":["redis 8.6.3"],"published":"2026-05-05","updated":"2026-07-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-23479","references":[{"url":"https://github.com/redis/redis/releases/tag/8.6.3","label":"security-advisories@github.com"},{"url":"https://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3","label":"security-advisories@github.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:14316","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25216","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25219","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25925","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26306","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26540","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:7662","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-23479","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2466780","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23479.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"tags":["nvd","exploit-available"],"epss":0.01356,"epssPercentile":0.69986,"ingestedAt":"2026-07-16T12:53:56.043Z","exploits":{"github":4,"githubRepos":["https://github.com/HackSpeak/CVE-2026-23479","https://github.com/pduggusa/redis-cve-2026-23479-check","https://github.com/v1c0mmrt/redis-cve-2026-23479-scanner"],"checkedAt":"2026-09-21T15:28:30.387Z"},"exploitAvailable":true,"slug":"CVE-2026-23479","body":"## Overview\n\nRedis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.\n\n## Affected\n\n- `redis >= 7.2.0, < 8.6.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `redis 8.6.3`","depth":"midnight","depthScore":61,"depthScoreParts":{"impact":48.4,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[{"seq":5017,"id":"CVE-2026-23479","ts":1788887228876,"field":"exploit_available","old":"false","new":"true"},{"seq":3900,"id":"CVE-2026-23479","ts":1788886359975,"field":"exploit_available","old":"true","new":"false"},{"seq":2722,"id":"CVE-2026-23479","ts":1788883025706,"field":"exploit_available","old":"false","new":"true"},{"seq":1751,"id":"CVE-2026-23479","ts":1788882429732,"field":"exploit_available","old":"true","new":"false"},{"seq":857,"id":"CVE-2026-23479","ts":1788881862760,"field":"exploit_available","old":"false","new":"true"}]}