CVE-2026-21864

Source
https://cve.org/CVERecord?id=CVE-2026-21864
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21864.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-21864
Aliases
  • GHSA-mc2g-h759-3qw2
Published
2026-02-24T00:24:15Z
Modified
2026-08-12T03:51:37Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Remote DoS from malformed RESTORE command
Details

Valkey-Bloom is a Rust based Valkey module which brings a Bloom Filter (Module) data type into the Valkey distributed key-value database. Prior to commit a68614b6e3845777d383b3a513cedcc08b3b7ccd, a specially crafted RESTORE command can cause Valkey to hit an assertion, causes the server to shutdown. Valkey modules are required to handle errors in RDB parsing by using VALKEYMODULE_OPTIONS_HANDLE_IO_ERRORS flag. If this flag is not set, errors encountered during parsing result in a system assertion which shuts down the system. Even though the Valkey-bloom module correctly handled the parsing, it did not originally set the flag. Commit a68614b6e3845777d383b3a513cedcc08b3b7ccd contains a patch. One may mitigate this defect by disabling the RESTORE command if it is unused by one's application.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-20"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21864.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "fixed":  "a68614b6e3845777d383b3a513cedcc08b3b7ccd"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/valkey-io/valkey-bloom

Affected ranges

Type
GIT
Repo
https://github.com/valkey-io/valkey-bloom
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:lfprojects:valkey-bloom:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.0.1"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.0.0
1.0.0-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21864.json"