Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-81934

Опубликовано: 27 авг. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.

EPSS

Процентиль: 36%
0.00435
Низкий

7.1 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.1
ubuntu
20 дней назад

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.

CVSS3: 7.5
redhat
20 дней назад

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.

CVSS3: 7.1
debian
20 дней назад

Redis contains a use-after-free vulnerability in the 'tlsProcessPendin ...

suse-cvrf
8 дней назад

Security update for redis7

suse-cvrf
8 дней назад

Security update for redis

EPSS

Процентиль: 36%
0.00435
Низкий

7.1 High

CVSS3

Дефекты

CWE-416