<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T13:06:40.704259+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:64796</id>
    <title>ALSA-2026:64796 — Important: valkey security, bug fix, and enhancement update</title>
    <updated>2026-10-04T13:06:40.960194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: valkey, AlmaLinux:10: valkey-devel</p>
<p>Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also.</p>
<p>Security Fix(es):</p>
<p>* redis: Redis: Remote Code Execution via specially crafted RESTORE payload (CVE-2026-66373)
  * valkey: Valkey: Remote code execution via use-after-free in stream deserialization (CVE-2026-63639)
  * valkey: Valkey: Remote code execution via TLS pending-data processing use-after-free (CVE-2026-56684)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [Tracker] Rebase valkey to 8.0.10 (JIRA:AlmaLinux-216776)</p>
<p>For more details about the security issue(s), including the im…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:64796"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-63639</id>
    <title>BELL-CVE-2026-63639</title>
    <updated>2026-10-04T13:06:40.960284+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: redis, Alpaquita:25: valkey, Alpaquita:stream: valkey</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-63639"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-valkey-2026-63639</id>
    <title>BIT-valkey-2026-63639 — Valkey: UAF in stream deserialization may lead to remote code execution</title>
    <updated>2026-10-04T13:06:40.960311+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: valkey</p>
<p>Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-valkey-2026-63639"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-357025</id>
    <title>EUVD-2026-357025</title>
    <updated>2026-10-04T13:06:40.960335+00:00</updated>
    <content>EUVD-2026-357025</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-357025"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63639</id>
    <title>fkie_cve-2026-63639</title>
    <updated>2026-10-04T13:06:40.960347+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63639"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-63639</id>
    <title>msrc_CVE-2026-63639 — Valkey: UAF in stream deserialization may lead to remote code execution</title>
    <updated>2026-10-04T13:06:40.960370+00:00</updated>
    <content>msrc_CVE-2026-63639</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-63639"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11381-1</id>
    <title>openSUSE-SU-2026:11381-1 — valkey-9.1.1-1.1 on GA media</title>
    <updated>2026-10-04T13:06:40.960387+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>valkey-9.1.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11381-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:61884</id>
    <title>RHSA-2026:61884 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-04T13:06:40.960403+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>valkey: Valkey: Remote code execution via TLS pending-data processing use-after-free valkey: Valkey: Remote code execution via use-after-free in stream deserialization valkey: Valkey: Use-after-free vulnerability in Blocked-on-keys subsystem valkey: Valkey: Denial of Service via double free in Module Timer subsystem</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:61884"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:64796</id>
    <title>RLSA-2026:64796 — Important: valkey security, bug fix, and enhancement update</title>
    <updated>2026-10-04T13:06:40.960424+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: valkey</p>
<p>Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets.  You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set.  In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log.  Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth.  Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache.  You can use Valkey from most programming languages also.</p>
<p>Security Fix(es):</p>
<p>* redis: Redis: Remote Code Execution via specially crafted RESTORE payload (CVE-2026-66373)</p>
<p>* valkey: Valkey: Remote code execution via use-after-free in stream deserialization (CVE-2026-63639)</p>
<p>* valkey: Valkey: Remote code execution via TLS pending-data processing use-after-free (CVE-2026-56684)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [Tracker] Rebase valkey to 8.0.10 (JIRA:Rocky Linux-216776)</p>
<p>For more details about the security issue(s), including the impact, a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:64796"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:3483-1</id>
    <title>SUSE-SU-2026:3483-1 — Security update for valkey</title>
    <updated>2026-10-04T13:06:40.960460+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for valkey</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:3483-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63639</id>
    <title>UBUNTU-CVE-2026-63639</title>
    <updated>2026-10-04T13:06:40.960477+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:24.04:LTS: valkey, Ubuntu:26.04:LTS: valkey</p>
<p>Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63639"/>
  </entry>
</feed>
