Valkey
This hub aggregates every CVE we track for Valkey, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
12
CVEs tracked
1
Critical
6
High
0
In CISA KEV
Severity distribution
HIGH6LOW4MEDIUM1CRITICAL1
Monthly trend
0
0
0
0
0
0
1
0
1
0
0
0
1
0
0
0
3
0
0
0
0
0
4
2
2024-102026-09
Latest CVEs
The 12 most recently published vulnerabilities affecting Valkey.
- CVE-2026-86227valkey-io valkey kvstore.c kvstoreGetHashtable out-of-bounds3.1
- CVE-2026-85522valkey-io valkey Slot Migration cluster_migrateslots.c createSlotImportJob out-of-bounds5.3
- CVE-2026-82677valkey-io valkey Module Timer module.c moduleTimerHandler double free2.4
- CVE-2026-82631valkey-io valkey Blocked-on-keys blocked.c handleClientsBlockedOnKey use after free2.2
- CVE-2026-63639Valkey: UAF in stream deserialization may lead to remote code execution8.8
- CVE-2026-56684Valkey: TLS pending-data processing use-after-free may allow remote code execution7.5
- CVE-2026-27623Valkey has Pre-Authentication DOS from malformed RESP request7.5
- CVE-2026-21863Malformed Valkey Cluster bus message can lead to Remote DoS7.5
- CVE-2025-67733Valkey Affected by RESP Protocol Injection via Lua error_reply8.5
- CVE-2025-49844Redis Lua Use-After-Free may lead to remote code execution9.9
- CVE-2025-49112setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.3.1
- CVE-2025-21605Redis DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated client7.5
Product normalization is registry-driven with AI assist and human review. How it works