PT-2026-21548 · Valkey+1 · Valkey+1
Eliyacohen-Hub
·
Published
2026-02-23
·
Updated
2026-04-30
·
CVE-2026-27623
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Valkey versions 9.0.0 through 9.0.2
Description
Valkey, a distributed key-value database, is susceptible to a denial of service condition. A remote attacker with network access can cause the system to terminate by triggering an assertion. This occurs because the system fails to reset networking state after processing an empty request, allowing a crafted request to be misinterpreted as a violation of server-side invariants, leading to a shutdown. As an additional mitigation, deployments should be properly isolated to restrict access to trusted users.
Recommendations
Update to version 9.0.3 or later.
Isolate Valkey deployments to limit network access to trusted users.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Os
Valkey