Software
Service
Insights
Case & Story
Dev Platform
Sign In
Public Notices
Redis Remote Code Execution Vulnerability
Jul. 28, 2026 GMT+8:00
1.Overview

Recently, we have noticed that Redis has released security-patched versions. A crafted stream RESTORE payload can cause two consumers to share the same NACK, triggering a use-after-free vulnerability which may lead to Remote Code Execution.

Redis is an open-source, network-supported, memory-based, distributed, and optionally persistent key-value pair storage database. If you are a Redis user, check your system and implement timely security hardening.

Reference:

https://github.com/redis/redis/security/advisories/GHSA-c8h9-259x-jff4

https://github.com/redis/redis/commit/41a958720e64e03576dd652d224aa46d22c096c3

2.Severity

important

(Severity: low, medium, important, and critical)

3.Affected Products

Affected versions:

Redis 6.2.22

Redis 7.2.14

Redis 7.4.9

Redis 8.2.7

Redis 8.4.4

Redis 8.6.4

Security versions:

Redis >= 6.2.23

Redis >= 7.2.15

Redis >= 7.4.10

Redis >= 8.2.8

Redis >= 8.4.5

Redis >= 8.6.5

Redis >= 8.8.0

4.Vulnerability Handling

This vulnerability has been fixed in later official versions. If your service version falls into the affected range, upgrade it to a latest secure version.

https://github.com/redis/redis/releases

Note: Before fixing vulnerabilities, back up your files and conduct a thorough test.

5.Technical Support

Get more professional support at any time

Contact Us

Email: GlobalTechnicalService@iwhalecloud.com
Contact Us