What is CVE-2026-63639?
This CVE describes a use-after-free vulnerability in Valkey's RESTORE command, triggered by a malformed RDB stream payload during stream consumer-group deserialization. It affects versions prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1; users should upgrade to the patched releases immediately.
Azərbaycanca: Bu CVE, Valkey distributed key-value verilənlər bazasında RESTORE əmri vasitəsilə xüsusi hazırlanmış RDB stream yükü göndərildikdə stream consumer-group deserialization zamanı use-after-free zəifliyinə səbəb olur. Təsirə məruz qalan versiyalar 7.2.14, 8.0.10, 8.1.9, 9.0.5 və 9.1.1-dən əvvəlki versiyalardır; istifadəçilər dərhal qeyd olunan versiyalara yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
Which command is exploited in CVE-2026-63639 to trigger the vulnerability in Valkey?
The vulnerability is exploited via the RESTORE command when a malformed RDB stream payload is sent.
What action should Valkey users take to mitigate CVE-2026-63639?
Users should immediately upgrade to patched releases: 7.2.14, 8.0.10, 8.1.9, 9.0.5, or 9.1.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.