{"id":"CVE-2026-63639","summary":"Valkey: UAF in stream deserialization may lead to remote code execution","details":"Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.","aliases":["GHSA-mvcj-73cw-22m4"],"modified":"2026-08-21T08:19:16.384019Z","published":"2026-08-18T14:23:52.508Z","related":["SUSE-SU-2026:3427-1","SUSE-SU-2026:3483-1","openSUSE-SU-2026:11381-1","openSUSE-SU-2026:21485-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63639.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-416"]},"references":[{"type":"WEB","url":"https://github.com/valkey-io/valkey/releases/tag/7.2.14"},{"type":"WEB","url":"https://github.com/valkey-io/valkey/releases/tag/8.0.10"},{"type":"WEB","url":"https://github.com/valkey-io/valkey/releases/tag/8.1.9"},{"type":"WEB","url":"https://github.com/valkey-io/valkey/releases/tag/9.0.5"},{"type":"WEB","url":"https://github.com/valkey-io/valkey/releases/tag/9.1.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63639.json"},{"type":"ADVISORY","url":"https://github.com/valkey-io/valkey/security/advisories/GHSA-mvcj-73cw-22m4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63639"},{"type":"FIX","url":"https://github.com/valkey-io/valkey/commit/06bc7768fe609f2054e69ccedefe7628f5675da9"},{"type":"FIX","url":"https://github.com/valkey-io/valkey/commit/509cb3c74e8cbc9c0498ebe8b6c93dcd605e7271"},{"type":"FIX","url":"https://github.com/valkey-io/valkey/commit/98465eaffe3f95524a5046318bfbc4bdb9798291"},{"type":"FIX","url":"https://github.com/valkey-io/valkey/commit/e95911d4d65be8789fa3705f44d7ed1e65378445"},{"type":"FIX","url":"https://github.com/valkey-io/valkey/commit/f8d2027e8d4df790ac04974bf606408c8ea62778"},{"type":"FIX","url":"https://github.com/valkey-io/valkey/pull/4073"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/valkey-io/valkey","events":[{"introduced":"0"},{"introduced":"2b5c7a0dbd61fd4281ef6166b7d119ba7fe7368c"},{"introduced":"67c8683792fc9ab7e295f833478eca180c5e4691"},{"introduced":"5018b12b0de2d2322a1bbf6b041c43740587c0f2"},{"introduced":"c9e8005e9d0ec817e26c7db318861cb821409249"},{"fixed":"499cfb9431c7cebec4d91f81bb4932a742a8c8ae"},{"fixed":"23b3f6bb66c19502225a40e7aeec9e1be76456c1"},{"fixed":"a9245aaf3286dee1795763661f0da6886acd8ef4"},{"fixed":"a253513ac7ff5790ca119053f3c7fbca4fdaad44"},{"fixed":"d27f9ba65a04e80d9c417112a7621fc98a56f70d"},{"fixed":"06bc7768fe609f2054e69ccedefe7628f5675da9"},{"fixed":"509cb3c74e8cbc9c0498ebe8b6c93dcd605e7271"},{"fixed":"98465eaffe3f95524a5046318bfbc4bdb9798291"},{"fixed":"e95911d4d65be8789fa3705f44d7ed1e65378445"},{"fixed":"f8d2027e8d4df790ac04974bf606408c8ea62778"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"7.2.14"},{"introduced":"8.0.0"},{"fixed":"8.0.10"},{"introduced":"8.1.0"},{"fixed":"8.1.9"},{"introduced":"9.0.0"},{"fixed":"9.0.5"},{"introduced":"9.1.0"},{"fixed":"9.1.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["9.1.0","9.1","9.0.4","8.1.8","8.0.9","8.1.7","7.2.13","8.0.7","8.1.6","9.0.3","7.2.12","9.0.2","8.1.5","9.0.1","9.0.0","7.2.11","8.0.6","8.1.4","7.2.10","8.0.5","8.0.4","8.1.3","8.0.3","8.1.2","7.2.9","8.1.1","8.1.0","7.2.8","8.0.2","7.2.7","8.0.1","8.0.0","7.2.6","7.2.5","7.2.5-rc1","7.2.4-rc1","7.2.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63639.json","vanir_signatures_modified":"2026-08-21T08:19:16Z","vanir_signatures":[{"digest":{"length":23591,"function_hash":"230768877839611101054266632653368496"},"id":"CVE-2026-63639-00f94091","signature_type":"Function","signature_version":"v1","source":"https://github.com/valkey-io/valkey/commit/e95911d4d65be8789fa3705f44d7ed1e65378445","target":{"file":"src/rdb.c","function":"rdbLoadObject"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/valkey-io/valkey/commit/509cb3c74e8cbc9c0498ebe8b6c93dcd605e7271","target":{"file":"src/rdb.c","function":"rdbLoadObject"},"deprecated":false,"digest":{"function_hash":"190544403724282786927446598291365725110","length":25013},"id":"CVE-2026-63639-55fc876e","signature_type":"Function"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/valkey-io/valkey/commit/06bc7768fe609f2054e69ccedefe7628f5675da9","target":{"file":"src/rdb.c"},"deprecated":false,"digest":{"line_hashes":["244415621463808803534515582580094818674","250433548265456674924563231111053879241","154392023832950776650256860880923554603"],"threshold":0.9},"id":"CVE-2026-63639-74e1321c"},{"deprecated":false,"digest":{"line_hashes":["244415621463808803534515582580094818674","250433548265456674924563231111053879241","154392023832950776650256860880923554603"],"threshold":0.9},"id":"CVE-2026-63639-7a410202","signature_type":"Line","signature_version":"v1","source":"https://github.com/valkey-io/valkey/commit/98465eaffe3f95524a5046318bfbc4bdb9798291","target":{"file":"src/rdb.c"}},{"id":"CVE-2026-63639-7d8ae8dc","signature_type":"Function","signature_version":"v1","source":"https://github.com/valkey-io/valkey/commit/f8d2027e8d4df790ac04974bf606408c8ea62778","target":{"function":"rdbLoadObject","file":"src/rdb.c"},"deprecated":false,"digest":{"function_hash":"287353720323192030297397996837231637699","length":23619}},{"target":{"file":"src/rdb.c","function":"rdbLoadObject"},"deprecated":false,"digest":{"function_hash":"212916778563393476109431128336851754874","length":23584},"id":"CVE-2026-63639-9124e9c8","signature_type":"Function","signature_version":"v1","source":"https://github.com/valkey-io/valkey/commit/98465eaffe3f95524a5046318bfbc4bdb9798291"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/valkey-io/valkey/commit/06bc7768fe609f2054e69ccedefe7628f5675da9","target":{"file":"src/rdb.c","function":"rdbLoadObject"},"deprecated":false,"digest":{"function_hash":"131976171611182190110098626164708744336","length":24119},"id":"CVE-2026-63639-c101b93f"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/valkey-io/valkey/commit/f8d2027e8d4df790ac04974bf606408c8ea62778","target":{"file":"src/rdb.c"},"deprecated":false,"digest":{"line_hashes":["244415621463808803534515582580094818674","250433548265456674924563231111053879241","154392023832950776650256860880923554603"],"threshold":0.9},"id":"CVE-2026-63639-efbc0c10"},{"id":"CVE-2026-63639-fe4820c0","signature_type":"Line","signature_version":"v1","source":"https://github.com/valkey-io/valkey/commit/509cb3c74e8cbc9c0498ebe8b6c93dcd605e7271","target":{"file":"src/rdb.c"},"deprecated":false,"digest":{"line_hashes":["244415621463808803534515582580094818674","250433548265456674924563231111053879241","154392023832950776650256860880923554603"],"threshold":0.9}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}