CVE-2026-81934

Source
https://cve.org/CVERecord?id=CVE-2026-81934
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-81934.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-81934
Downstream
Related
Published
2026-08-27T19:40:15Z
Modified
2026-09-09T12:11:39Z
Severity
  • 7.5 (High) CVSS_V4 - CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Redis TLS pending-data list use-after-free
Details

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.

Database specific
{
    "cna_assigner": "cisa-cg",
    "cwe_ids": [
        "CWE-416"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81934.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "8.2.0-46"
                },
                {
                    "fixed": "8.0.20-96"
                },
                {
                    "fixed": "7.22.2-179"
                },
                {
                    "fixed": "7.8.6-303"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/redis/redis

Affected ranges

Type
GIT
Repo
https://github.com/redis/redis
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "8.8.2"
        },
        {
            "fixed": "8.2.9"
        },
        {
            "fixed": "8.4.6"
        },
        {
            "fixed": "8.6.6"
        },
        {
            "fixed": "8.10.1"
        },
        {
            "fixed": "7.4.11"
        },
        {
            "fixed": "6.2.24"
        },
        {
            "fixed": "7.2.16"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.3.6
2.*
2.2-alpha0
2.2-alpha1
2.2-alpha2
2.2-alpha3
2.2-alpha4
2.2-alpha5
2.2-alpha6
2.2.0-rc1
2.3-alpha0
6.*
6.2-rc1
6.2-rc2
6.2-rc3
6.2.0
6.2.1
6.2.10
6.2.11
6.2.12
6.2.13
6.2.14
6.2.15
6.2.16
6.2.17
6.2.18
6.2.19
6.2.2
6.2.20
6.2.21
6.2.22
6.2.23
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
7.*
7.2-rc1
7.2-rc2
7.2-rc3
7.2.0
7.2.1
7.2.10
7.2.11
7.2.12
7.2.13
7.2.14
7.2.15
7.2.2
7.2.3
7.2.4
7.2.5
7.2.6
7.2.7
7.2.8
7.2.9
7.4-rc1
7.4-rc2
7.4.0
7.4.1
7.4.10
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.4.8
7.4.9
8.*
8.10-m01-int
8.10-m02-int
8.10-m03-int
8.10-m04-int
8.10-rc1
8.10-rc2
8.10.0
8.2-int
8.2-m01
8.2-m01-int
8.2-m01-int2
8.2-rc1
8.2-rc1-int
8.2.0
8.2.1
8.2.1-int
8.2.2
8.2.2-int
8.2.3
8.2.4
8.2.5
8.2.6
8.2.7
8.2.8
8.4-int
8.4-int2
8.4-int3
8.4-m01-int
8.4-rc1
8.4-rc1-int
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.4.5
8.6-rc1
8.6.0
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.8-m02
8.8-m03
8.8-rc1
8.8.0
8.8.1
v1.*
v1.3.10
v1.3.11
v1.3.7
v1.3.8
v1.3.9
v2.*
v2.0.0-rc1
v2.1.1-watch
Other
vm-playpen

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-81934.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "128330966063640458177165127154043914103",
                "68565331001453725688164561068389013121",
                "293366915637562491569134048175105274626",
                "238356628685182825189061293718483789312",
                "251010466998149454815479957341446555758",
                "91211893321144979629165339915411646108",
                "222235737238863679436292414109635472321",
                "162414704591053017749326517923089046738",
                "198071868249015045736900182625827027817",
                "281756496751194748324509474716653118956",
                "126627964511863400972304111509054999908"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-81934-a82e2886",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834",
        "target": {
            "file": "src/tls.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "129583593005033021929188056092136550346",
            "length": 313
        },
        "id": "CVE-2026-81934-f9a5c822",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834",
        "target": {
            "file": "src/tls.c",
            "function": "tlsProcessPendingData"
        }
    }
]
vanir_signatures_modified
"2026-09-02T08:13:46Z"