8.8
HIGH CVSS 3.1
CVE-2026-23479
redis-server use-after-free in unblock client flow may allow remote code execution
Description

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.

INFO

Published Date :

May 5, 2026, 5:17 p.m.

Last Modified :

May 6, 2026, 3:53 p.m.

Remotely Exploit :

Yes !
Affected Products

The following products are affected by CVE-2026-23479 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Redis redis
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH [email protected]
CVSS 4.0 HIGH [email protected]
Solution
Update Redis to version 8.6.3 or later to fix a use-after-free vulnerability.
  • Update Redis to version 8.6.3 or later.
  • Apply the vendor-provided patch.
Public PoC/Exploit Available at Github

CVE-2026-23479 has a 9 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2026-23479.

URL Resource
https://github.com/redis/redis/releases/tag/8.6.3 Release Notes
https://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3 Vendor Advisory
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-23479 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-23479 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

CVE-2026-23479 Redis Use-After-Free vulnerability detection tool

Python

Updated: 5 days, 18 hours ago
0 stars 0 fork 0 watcher
Born at : June 11, 2026, 3:43 p.m. This repo has been linked 1 different CVEs too.

None

Updated: 1 week ago
0 stars 0 fork 0 watcher
Born at : June 9, 2026, 11:16 a.m. This repo has been linked 1 different CVEs too.

None

Updated: 1 week, 2 days ago
0 stars 0 fork 0 watcher
Born at : June 7, 2026, 9:20 p.m. This repo has been linked 1 different CVEs too.

Safe read-only version checker + Sigma rule for Redis CVE-2026-23479 (authenticated use-after-free → RCE). Find exposed instances, patch left-of-boom. By DugganUSA.

Python

Updated: 1 week, 5 days ago
0 stars 0 fork 0 watcher
Born at : June 4, 2026, 8:09 p.m. This repo has been linked 1 different CVEs too.

None

Python

Updated: 1 week, 4 days ago
0 stars 0 fork 0 watcher
Born at : May 27, 2026, 4:28 p.m. This repo has been linked 10 different CVEs too.

Desc "Fix Redis CVE ultil 20260508-10h51 GMT+7"

Shell

Updated: 1 month, 1 week ago
0 stars 0 fork 0 watcher
Born at : May 8, 2026, 3:51 a.m. This repo has been linked 5 different CVEs too.

Automated GitHub Actions workflow that fetches and updates the latest cybersecurity news every Tuesday and Thursday using RSS feeds.

Updated: 1 week, 5 days ago
0 stars 0 fork 0 watcher
Born at : March 25, 2026, 8:04 a.m. This repo has been linked 2 different CVEs too.

None

Updated: 1 week, 5 days ago
0 stars 0 fork 0 watcher
Born at : Jan. 10, 2026, 2:42 p.m. This repo has been linked 1 different CVEs too.

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

security cve exploit poc vulnerability

Updated: 1 week, 2 days ago
7810 stars 1261 fork 1261 watcher
Born at : Dec. 8, 2019, 1:03 p.m. This repo has been linked 718 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-23479 vulnerability anywhere in the article.

  • The Hacker News
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portal ... Read more

Published Date: Jun 15, 2026 (2 days, 4 hours ago)
  • The Hacker News
Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vul ... Read more

Published Date: Jun 13, 2026 (3 days, 21 hours ago)
  • The Hacker News
China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself. Sygnia, which tracks the group as Ve ... Read more

Published Date: Jun 12, 2026 (4 days, 16 hours ago)
  • The Hacker News
LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution. LangGraph ... Read more

Published Date: Jun 12, 2026 (5 days, 1 hour ago)
  • The Hacker News
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hard ... Read more

Published Date: Jun 11, 2026 (5 days, 14 hours ago)
  • The Hacker News
New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day after they published an exploit for Microsoft Defender. " ... Read more

Published Date: Jun 11, 2026 (5 days, 17 hours ago)
  • The Hacker News
The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leverag ... Read more

Published Date: Jun 11, 2026 (5 days, 18 hours ago)
  • The Hacker News
ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories

It's been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there's a supply chain attack kit in a public repo, a $5,000-a-mon ... Read more

Published Date: Jun 11, 2026 (5 days, 21 hours ago)
  • The Hacker News
China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

Cybersecurity researchers have warned of a "resurgence and expansion" of JDY, a covert network associated with China-nexus state-sponsored threat actors. "The JDY botnet comprises over 1,500 SOHO [sma ... Read more

Published Date: Jun 10, 2026 (6 days, 19 hours ago)
  • The Hacker News
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure. The security fl ... Read more

Published Date: Jun 10, 2026 (6 days, 19 hours ago)
  • The Hacker News
Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE

A high-severity unpatched security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, according to f ... Read more

Published Date: Jun 10, 2026 (6 days, 20 hours ago)
  • The Hacker News
CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitati ... Read more

Published Date: Jun 10, 2026 (6 days, 20 hours ago)
  • The Hacker News
Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs

Microsoft on Tuesday released fixes for a record 206 security vulnerabilities impacting its software portfolio, including three flaws that have been publicly disclosed at the time of release. Of the 2 ... Read more

Published Date: Jun 10, 2026 (1 week ago)
  • The Hacker News
Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards

On June 9, Anthropic released Claude Fable 5, the most capable model it has ever made, generally available. It also did something unusual: it shipped one model as two products, split not by capability ... Read more

Published Date: Jun 10, 2026 (1 week ago)
  • The Hacker News
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

The anonymous security researcher going by the name Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit for yet another Microsoft Defender zero-day named RoguePlanet. ... Read more

Published Date: Jun 10, 2026 (1 week ago)
  • The Hacker News
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

Cybersecurity researchers have flagged half a dozen vulnerabilities in protobuf.js, a JavaScript and TypeScript implementation of Protocol Buffers (Protobuf), that, if successfully exploited, could re ... Read more

Published Date: Jun 10, 2026 (1 week ago)
  • The Hacker News
Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI t ... Read more

Published Date: Jun 03, 2026 (1 week, 6 days ago)
  • CybersecurityNews
Critical Redis Vulnerabilities Enables Remote Code Execution Attacks

Five dangerous vulnerabilities in Redis expose Redis Cloud, Redis Software, and all open-source community editions to potential remote code execution, giving authenticated attackers a direct path to c ... Read more

Published Date: May 07, 2026 (1 month, 1 week ago)

The following table lists the changes that have been made to the CVE-2026-23479 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    May. 06, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Added CPE Configuration OR *cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:* versions from (including) 7.2.0 up to (excluding) 8.6.3
    Added Reference Type GitHub, Inc.: https://github.com/redis/redis/releases/tag/8.6.3 Types: Release Notes
    Added Reference Type GitHub, Inc.: https://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3 Types: Vendor Advisory
  • New CVE Received by [email protected]

    May. 05, 2026

    Action Type Old Value New Value
    Added Description Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
    Added CVSS V4.0 AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-416
    Added Reference https://github.com/redis/redis/releases/tag/8.6.3
    Added Reference https://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.