{"id":"CVE-2026-66373","details":"Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.","modified":"2026-08-18T17:41:56.606894654Z","published":"2026-07-25T00:08:35.982Z","related":["SUSE-SU-2026:3636-1","SUSE-SU-2026:3637-1","SUSE-SU-2026:3638-1","SUSE-SU-2026:3639-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66373.json","cna_assigner":"mitre","cwe_ids":["CWE-415"]},"references":[{"type":"WEB","url":"https://github.com/redis/redis/compare/8.6.4...8.8.0"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/08/msg00012.html"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=49024938"},{"type":"WEB","url":"https://x.com/Fried_rice/status/2080059356322918777"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66373.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66373"},{"type":"FIX","url":"https://github.com/redis/redis/pull/15081"},{"type":"PACKAGE","url":"https://github.com/berabuddies/redis-poc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/redis/redis","events":[{"introduced":"0"},{"fixed":"5a693aaed0842c4eef21c706b79fa49938ca9f6c"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"8.8.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["8.8-rc1","8.8-m03","8.8-m02","8.4-int","2.3-alpha0","2.2.0-rc1","2.2-alpha6","2.2-alpha5","2.2-alpha4","2.2-alpha3","2.2-alpha2","2.2-alpha1","2.2-alpha0","v2.0.0-rc1","v2.1.1-watch","v1.3.11","v1.3.10","v1.3.9","v1.3.8","v1.3.7","1.3.6","vm-playpen"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66373.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}