CVE-2026-63639
Public on 2026-07-27
Modified on 2026-07-27
Description
An authenticated user may use a specially crafted RESTORE command to inject a malformed RDB payload containing duplicate Pending Entry List (PEL) assignments. This triggers a use-after-free during stream consumer group deserialization or consumer deletion, potentially leading to remote code execution.
The problem exists in all versions of Valkey.
The problem exists in all versions of Valkey.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2023 | redis6 | No Fix Planned | ||
| Amazon Linux 2023 | valkey | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |