CVE-2026-21864

Source
https://cve.org/CVERecord?id=CVE-2026-21864
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21864.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-21864
Aliases
  • GHSA-mc2g-h759-3qw2
Published
2026-02-24T00:24:15.677Z
Modified
2026-02-28T07:33:14.026495Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Remote DoS from malformed RESTORE command
Details

Valkey-Bloom is a Rust based Valkey module which brings a Bloom Filter (Module) data type into the Valkey distributed key-value database. Prior to commit a68614b6e3845777d383b3a513cedcc08b3b7ccd, a specially crafted RESTORE command can cause Valkey to hit an assertion, causes the server to shutdown. Valkey modules are required to handle errors in RDB parsing by using VALKEYMODULE_OPTIONS_HANDLE_IO_ERRORS flag. If this flag is not set, errors encountered during parsing result in a system assertion which shuts down the system. Even though the Valkey-bloom module correctly handled the parsing, it did not originally set the flag. Commit a68614b6e3845777d383b3a513cedcc08b3b7ccd contains a patch. One may mitigate this defect by disabling the RESTORE command if it is unused by one's application.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21864.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-20"
    ]
}
References

Affected packages

Git / github.com/valkey-io/valkey-bloom

Affected ranges

Type
GIT
Repo
https://github.com/valkey-io/valkey-bloom
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21864.json"