PT-2026-21548 · Valkey+1 · Valkey+1

Eliyacohen-Hub

·

Published

2026-02-23

·

Updated

2026-04-30

·

CVE-2026-27623

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Valkey versions 9.0.0 through 9.0.2
Description Valkey, a distributed key-value database, is susceptible to a denial of service condition. A remote attacker with network access can cause the system to terminate by triggering an assertion. This occurs because the system fails to reset networking state after processing an empty request, allowing a crafted request to be misinterpreted as a violation of server-side invariants, leading to a shutdown. As an additional mitigation, deployments should be properly isolated to restrict access to trusted users.
Recommendations Update to version 9.0.3 or later. Isolate Valkey deployments to limit network access to trusted users.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07362
BIT-VALKEY-2026-27623
CVE-2026-27623
GHSA-93P9-5VC7-8WGR
OPENSUSE-SU-2026:10266-1

Affected Products

Red Os
Valkey