CVE-2026-56684: Valkey-Io Valkey

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-free that can crash the server or potentially allow remote code execution when TLS is enabled. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.

Affected products

  • Valkey-Io Valkey: before 7.2.14 (fixed in 7.2.14); from 8.0.0, before 8.0.10 (fixed in 8.0.10); from 8.1.0, before 8.1.9 (fixed in 8.1.9); from 9.0.0, before 9.0.5 (fixed in 9.0.5); from 9.1.0, before 9.1.1 (fixed in 9.1.1)

Published 2026-08-18. Last modified 2026-09-18.