CVE-2026-23631
redis-server Lua use-after-free may allow remote code execution
Description
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and Moreen·The Hacker News· Roundup GitHub repositories supply-chain
- Redis DarkReplica Exploit: Full PoC Code and Technical Details Releaseden-us·Daily CyberSecurity (securityonline.info)·
- Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)en·The Hacker News· PoC Redis rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-23631 and every CVE in our database. Create a free account — no credit card required.
Create Free Account