Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98240.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-98240
Upstream
Published
2026-08-27T20:18:57Z
Modified
2026-09-03T05:27:10Z
Summary
CVE-2026-81934 affecting package valkey 8.0.10-1
Details

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.

References

Affected packages

Azure Linux:3 / valkey

Package

Name
valkey
Purl
pkg:rpm/azure-linux/valkey

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
8.0.10-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98240.json"