BIT-keydb-2026-23631

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/keydb/BIT-keydb-2026-23631.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-keydb-2026-23631
Aliases
Published
2026-05-07T08:42:54Z
Modified
2026-09-10T16:01:41Z
Summary
redis-server Lua use-after-free may allow remote code execution
Details

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.

Database specific
{
    "cpes": [
        "cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / keydb

Package

Name
keydb
Purl
pkg:bitnami/keydb

Severity

  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
7.2.0
Fixed
7.2.14
Introduced
7.3.0
Fixed
7.4.9
Introduced
8.0.0
Fixed
8.2.6
Introduced
8.3.0
Fixed
8.4.3
Introduced
8.5.0
Fixed
8.6.3

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/keydb/BIT-keydb-2026-23631.json"