Back to vendor advisories
Microsoft Security Response CenterCVE-2026-66373

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.

Mariner

7.5CVSS out of 10High severity
Scope

What the vendor says is affected

  • azl3 valkey 8.0.9-1 on Azure Linux 3.0
  • azl3 valkey 8.0.10-1 on Azure Linux 3.0
Timeline

When this advisory changed

  1. Published by Microsoft Security Response Center

    The publication date reported by the vendor.

  2. Updated by Microsoft Security Response Center

    The vendor changed the advisory after it was first published.

  3. Added to SecurityAlert

    We collected the advisory from the official source.

  4. Confirmed at the source

    Our collector saw this advisory during a later source check.

Vulnerabilities

CVEs named in this advisory