A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-415"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82677.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82677.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"121424084538841979303371684067119623936",
"184172033092886764967057584451512310012",
"23763138507377313270743289103296802350",
"53557224944119540552029822075154181490",
"335627178093124097414656039686885628636",
"180911272441217126914259233718729396533",
"76251647179270472373396840484895292057",
"191059738845168834836956503359775452072",
"70926986156126347839965255119912938867",
"232798187513881962608299090294875735235"
],
"threshold": 0.9
},
"id": "CVE-2026-82677-3713ad9c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/valkey-io/valkey/commit/b349fe2821e3998534b1454c1b64a478daf8c6b7",
"target": {
"file": "tests/modules/timer.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "181002746710278198057415400298666164805",
"length": 926
},
"id": "CVE-2026-82677-bfdace78",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/valkey-io/valkey/commit/b349fe2821e3998534b1454c1b64a478daf8c6b7",
"target": {
"file": "src/module.c",
"function": "moduleTimerHandler"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "223872119029403364301683718358855343745",
"length": 622
},
"id": "CVE-2026-82677-d2060176",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/valkey-io/valkey/commit/b349fe2821e3998534b1454c1b64a478daf8c6b7",
"target": {
"file": "tests/modules/timer.c",
"function": "ValkeyModule_OnLoad"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"296600120506627947378667650651849215320",
"249043444977729417223967385422382802430",
"3896363355649836795860685149567679731",
"66443840598751723807212496914308728363",
"217843375045813198240432110884070006111",
"277660404437707427574304317542096099240",
"177115730006976117751042488760995221490",
"68512649465367817025158534011933578786",
"253505895709609749406755755212734231586",
"65261301973095328416481032669559439244",
"142927469614529443823430184823995116761",
"307598280944125561519196389387933560061"
],
"threshold": 0.9
},
"id": "CVE-2026-82677-e076e4e8",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/valkey-io/valkey/commit/b349fe2821e3998534b1454c1b64a478daf8c6b7",
"target": {
"file": "src/module.c"
}
}
]
"2026-09-02T08:05:45Z"