CVE-2026-82631

Source
https://cve.org/CVERecord?id=CVE-2026-82631
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82631.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82631
Downstream
Published
2026-08-31T07:45:13.359Z
Modified
2026-09-02T08:08:03.379486Z
Severity
  • 1.2 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
valkey-io valkey Blocked-on-keys blocked.c handleClientsBlockedOnKey use after free
Details

A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The manipulation results in use after free. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The patch is identified as b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b. Applying a patch is advised to resolve this issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82631.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-416"
    ]
}
References

Affected packages

Git / github.com/valkey-io/valkey

Affected ranges

Type
GIT
Repo
https://github.com/valkey-io/valkey
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "9.1.0"
        },
        {
            "last_affected": "9.1.0"
        }
    ]
}

Affected versions

9.*
9.1.0

Database specific

vanir_signatures
[
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "224212326133507980516476871434833225764",
                "180911272441217126914259233718729396533",
                "76251647179270472373396840484895292057",
                "107800714045205141807014340762746926866",
                "185665389199785095687028863708427211703"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-82631-504c8bcb",
        "target": {
            "file": "tests/modules/blockonkeys.c"
        },
        "source": "https://github.com/valkey-io/valkey/commit/b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 728.0,
            "function_hash": "246169775744230407966315073595625919800"
        },
        "id": "CVE-2026-82631-74665c71",
        "target": {
            "function": "handleClientsBlockedOnKey",
            "file": "src/blocked.c"
        },
        "source": "https://github.com/valkey-io/valkey/commit/b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 2119.0,
            "function_hash": "115977004619012109065296146380830898796"
        },
        "id": "CVE-2026-82631-8b57d61f",
        "target": {
            "function": "ValkeyModule_OnLoad",
            "file": "tests/modules/blockonkeys.c"
        },
        "source": "https://github.com/valkey-io/valkey/commit/b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "160692568258425592405757227686407219811",
                "123563816099661161587764117289571183922",
                "202700731399895605414755438673930269808",
                "278823690545426334719441701333950642347",
                "261857039035298197721982772646061177326",
                "297990788943995378858675851745255264843",
                "150985041832129135443991331363748982923",
                "110765998793895318489718687274492570696",
                "156008437170646869390169523302166225491",
                "24906264981807179007779248023450493340",
                "71989013983000452619034111722700885273",
                "333975116974296080170551909932216584306",
                "137273233740802796325660789051528006838",
                "108587633537507210242609878158511307392",
                "122389095718077750204702522837943200772"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-82631-ae5e80aa",
        "target": {
            "file": "src/blocked.c"
        },
        "source": "https://github.com/valkey-io/valkey/commit/b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b",
        "signature_version": "v1"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82631.json"
vanir_signatures_modified
"2026-09-02T08:08:03Z"