CVE-2026-66373High· 7.5▾ TwilightRedis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-79020Medium· 4.3chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-79020)
CVE-2026-89767Medium· 5.5kernel: ovl: fix double end_creating() on the casefold-mismatch path (CVE-2026-89767)
CVE-2026-80989High· 7.0kernel: net: thunderbolt: Mark the connection down when bringing it up fails (CVE-2026-80989)
CVE-2026-89563High· 7.0kernel: ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() (CVE-2026-89563)
CVE-2026-89582High· 7.0kernel: bnx2x: fix double free in bnx2x_init_firmware() error path (CVE-2026-89582)
CVE-2026-89741High· 7.0kernel: Revert "media: v4l2-dev: fix error handling in __video_register_device()" (CVE-2026-89741)