What is CVE-2026-56684?
In Valkey distributed key-value database, an authenticated attacker can trigger a use-after-free vulnerability in the `tlsProcessPendingData` function by issuing the `CLIENT KILL` command, which causes `connTLSClose` to delete an iterator's cached next node. This may lead to remote code execution or service disruption. Upgrading to versions after 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1 is recommended.
Azərbaycanca: Valkey paylanmış açar-dəyər verilənlər bazasında autentifikasiya olunmuş istifadəçi `CLIENT KILL` əmri ilə TLS bağlantısını idarə edən `tlsProcessPendingData` funksiyasında use-after-free zəifliyinə səbəb ola bilər. Bu zəiflikdən istifadə edərək uzaqdan kod icrası və ya xidmətin dayandırılması mümkündür. Valkey-in qeyd olunan versiyalarından əvvəlki versiyalar təsirlənir, yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
Which command can be used to exploit CVE-2026-56684?
An authenticated attacker can exploit this vulnerability by issuing the `CLIENT KILL` command.
In which Valkey versions is CVE-2026-56684 fixed?
This vulnerability is fixed in versions after 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.