Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.4

CVE-2026-81934: Redis with TLS may let remote attacker run commands

CVE-2026-81934 · published 18 days ago
Summary

If Redis is set up to use TLS, a coding error could let a stranger send specially crafted traffic and cause the server to run any command it wants. This could happen without any authentication and gives the attacker full control over the Redis service. Apply the latest Redis updates or disable TLS until the patch is installed.

What to do
  • Update bellsoft redis to version 7.2.16-r0.
  • Update redis redis to version 8.8.2 or later.
  • Update redis redis software (enterprise) to version 8.2.0-46 or later.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:Pro:14.04:LTS canonical redis All versions
redis redis 8.8.0
< 8.8.2
Debian:11 debian redis All versions
Debian:12 debian redis All versions
Debian:13 debian redis All versions
Debian:14 debian redis All versions
redis redis software (enterprise) < 8.2.0-46
Alpaquita:23 bellsoft redis >= 7.0.9-r0, < 7.2.16-r0
Fix: upgrade to 7.2.16-r0
Original advisory text
BELL-CVE-2026-81934
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.
References
Severity
8.4 High
CVSS 3.1: 9.8 (MITRE)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-416Use After Free
Timeline
Published3 Sep 2026
Updated21 Sep 2026
First seen27 Aug 2026
Track software like this
Free during beta