CVE-2026-81934: Redis
High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.
Affected products
- Redis Redis: before 8.8.2 (fixed in 8.8.2); before 8.2.9 (fixed in 8.2.9); before 8.4.6 (fixed in 8.4.6); before 8.6.6 (fixed in 8.6.6); before 8.10.1 (fixed in 8.10.1); before 7.4.11 (fixed in 7.4.11); …
- Redis Redis Software Enterprise: before 8.2.0-46 (fixed in 8.2.0-46); before 8.0.20-96 (fixed in 8.0.20-96); before 7.22.2-179 (fixed in 7.22.2-179); before 7.8.6-303 (fixed in 7.8.6-303)
Published 2026-08-27. Last modified 2026-08-31.