{"id":"CVE-2026-66373","title":"Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting…","summary":"Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-415","CWE-1341"],"published":"2026-07-25","updated":"2026-09-09","sourceUpdated":"2026-09-09T16:03:33.283","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-66373","references":[{"url":"https://github.com/berabuddies/redis-poc","label":"cve@mitre.org"},{"url":"https://github.com/redis/redis/compare/8.6.4...8.8.0","label":"cve@mitre.org"},{"url":"https://github.com/redis/redis/pull/15081","label":"cve@mitre.org"},{"url":"https://news.ycombinator.com/item?id=49024938","label":"cve@mitre.org"},{"url":"https://x.com/Fried_rice/status/2080059356322918777","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2026/08/msg00012.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/berabuddies/redis-poc","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-66373.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-66373"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2506985"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-66373"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66373"},{"url":"https://access.redhat.com/errata/RHSA-2026:64796"},{"url":"https://access.redhat.com/errata/RHSA-2026:64823"},{"url":"https://access.redhat.com/errata/RHSA-2026:67461"},{"url":"https://access.redhat.com/errata/RHSA-2026:64824"},{"url":"https://access.redhat.com/errata/RHSA-2026:65120"},{"url":"https://access.redhat.com/errata/RHSA-2026:64807"},{"url":"https://access.redhat.com/errata/RHSA-2026:43236"},{"url":"https://access.redhat.com/errata/RHSA-2026:68601"},{"url":"https://access.redhat.com/errata/RHSA-2026:69542"},{"url":"https://access.redhat.com/errata/RHSA-2026:69534"},{"url":"https://access.redhat.com/errata/RHSA-2026:69533"},{"url":"https://access.redhat.com/errata/RHSA-2026:69861"},{"url":"https://access.redhat.com/errata/RHSA-2026:69521"},{"url":"https://access.redhat.com/errata/RHSA-2026:69520"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00872,"epssPercentile":0.57104,"ingestedAt":"2026-09-09T16:14:05.510Z","vendor":"Red Hat","product":"Red Hat Enterprise Linux AppStream (v. 9)","affected":["enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","hardened_images"],"patched":["enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","hardened_images"],"slug":"CVE-2026-66373","body":"## Overview\n\nRedis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:64796** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64796)\n- **RHSA-2026:64823** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64823)\n- **RHSA-2026:67461** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67461)\n- **RHSA-2026:64824** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64824)\n- **RHSA-2026:65120** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65120)\n- **RHSA-2026:64807** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64807)\n- **RHSA-2026:43236** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43236)\n- **RHSA-2026:68601** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68601)\n- **RHSA-2026:69542** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69542)\n- **RHSA-2026:69534** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69534)\n- **RHSA-2026:69533** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69533)\n- **RHSA-2026:69861** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69861)\n- **RHSA-2026:69521** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69521)\n- **RHSA-2026:69520** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69520)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}