Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 21

Количество 21

suse-cvrf логотип

SUSE-SU-2026:0848-1

5 месяцев назад

Security update for valkey

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0685-1

5 месяцев назад

Security update for valkey

EPSS: Низкий
rocky логотип

RLSA-2026:3507

5 месяцев назад

Important: valkey security update

EPSS: Низкий
rocky логотип

RLSA-2026:3443

5 месяцев назад

Important: valkey security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-3507

5 месяцев назад

ELSA-2026-3507: valkey security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-3443

5 месяцев назад

ELSA-2026-3443: valkey security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20776-1

2 месяца назад

Security update for valkey

EPSS: Низкий
ubuntu логотип

CVE-2026-21863

5 месяцев назад

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-21863

5 месяцев назад

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-21863

5 месяцев назад

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-21863

5 месяцев назад

Malformed Valkey Cluster bus message can lead to Remote DoS

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-21863

5 месяцев назад

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-67733

5 месяцев назад

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.

CVSS3: 8.5
EPSS: Низкий
redhat логотип

CVE-2025-67733

5 месяцев назад

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2025-67733

5 месяцев назад

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.

CVSS3: 8.5
EPSS: Низкий
msrc логотип

CVE-2025-67733

5 месяцев назад

Valkey Affected by RESP Protocol Injection via Lua error_reply

CVSS3: 8.5
EPSS: Низкий
debian логотип

CVE-2025-67733

5 месяцев назад

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8 ...

CVSS3: 8.5
EPSS: Низкий
fstec логотип

BDU:2026-07339

5 месяцев назад

Уязвимость сервера структур данных Valkey, связанная с чтением за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-07333

5 месяцев назад

Уязвимость сервера структур данных Valkey, связанная с недостаточной нейтрализацией специальных элементов в запросе, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.1
EPSS: Низкий
redos логотип

ROS-20260430-73-0002

3 месяца назад

Уязвимость valkey

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2026:0848-1

Security update for valkey

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0685-1

Security update for valkey

5 месяцев назад
rocky логотип
RLSA-2026:3507

Important: valkey security update

5 месяцев назад
rocky логотип
RLSA-2026:3443

Important: valkey security update

5 месяцев назад
oracle-oval логотип
ELSA-2026-3507

ELSA-2026-3507: valkey security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-3443

ELSA-2026-3443: valkey security update (IMPORTANT)

5 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20776-1

Security update for valkey

2 месяца назад
ubuntu логотип
CVE-2026-21863

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-21863

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-21863

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
msrc логотип
CVE-2026-21863

Malformed Valkey Cluster bus message can lead to Remote DoS

CVSS3: 7.5
1%
Низкий
5 месяцев назад
debian логотип
CVE-2026-21863

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8 ...

CVSS3: 7.5
1%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-67733

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.

CVSS3: 8.5
1%
Низкий
5 месяцев назад
redhat логотип
CVE-2025-67733

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.

CVSS3: 7.1
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-67733

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.

CVSS3: 8.5
1%
Низкий
5 месяцев назад
msrc логотип
CVE-2025-67733

Valkey Affected by RESP Protocol Injection via Lua error_reply

CVSS3: 8.5
1%
Низкий
5 месяцев назад
debian логотип
CVE-2025-67733

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8 ...

CVSS3: 8.5
1%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-07339

Уязвимость сервера структур данных Valkey, связанная с чтением за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-07333

Уязвимость сервера структур данных Valkey, связанная с недостаточной нейтрализацией специальных элементов в запросе, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.1
1%
Низкий
5 месяцев назад
redos логотип
ROS-20260430-73-0002

Уязвимость valkey

CVSS3: 7.5
1%
Низкий
3 месяца назад

Уязвимостей на страницу