CVE-2026-66373

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
Configurations

No configuration.

History

27 Jul 2026, 14:17

Type Values Removed Values Added
References () https://github.com/berabuddies/redis-pocĀ - () https://github.com/berabuddies/redis-pocĀ -

25 Jul 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-25 01:16

Updated : 2026-07-28 05:17


NVD link : CVE-2026-66373

Mitre link : CVE-2026-66373

CVE.ORG link : CVE-2026-66373


JSON object : View

Products Affected

No product.

CWE
CWE-415

Double Free