Redis maintainers released security updates across multiple supported branches to fix several vulnerabilities in the in-memory database, including flaws that could cause denial of service, unauthorized information access, TLS certificate authentication bypass, and possible remote code execution during RDB loading. The most serious issues affect RDB parsing and include CVE-2026-62356, which stems from an incorrectly calculated buffer size that can trigger a heap out-of-bounds write, and another out-of-bounds slot ID flaw that could also enable injected code execution through memory corruption. Fixed versions include 8.10.1, 8.8.2, 8.6.6, 8.4.6, 8.2.9, 7.4.11, 7.2.16, and 6.2.24, and administrators were urged to update quickly.
Related hardening work in the Redis ecosystem shows additional scrutiny of corrupted RDB and RESTORE data handling. A published patch in the Valkey codebase rejects malformed stream consumer-group Pending Entries List data when a shared NACK appears across different consumers, treating the payload as a corrupt RDB and failing the load operation with a bad-format error. The fix adds validation and regression testing for crafted dump payloads, reinforcing concerns that malformed persistence data can be abused to crash services or potentially reach memory-corruption paths during database import and restore operations.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
A code commit added validation in RDB/RESTORE handling to reject corrupted stream consumer group data where a NACK is shared across different consumers, and included a regression test that verifies RESTORE fails on the malformed payload.
In July, an IT researcher reportedly found a total of 19 zero-day vulnerabilities in Redis using the Chinese AI system Kimi K3. The findings prompted Redis developers to prepare updated software packages.
Redis developers released updated versions 8.10.1, 8.8.2, 8.6.6, 8.4.6, 8.2.9, 7.4.11, 7.2.16, and 6.2.24 to fix multiple flaws affecting RDB loading, TLS certificate authentication, denial of service, and unauthorized information disclosure. One disclosed issue was CVE-2026-62356, a heap out-of-bounds write caused by an incorrectly calculated buffer size when loading RDB files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.