Executive brief
Redis is a widely used data storage system for caching and real-time data processing. A vulnerability in certain versions allows an attacker with valid login credentials to execute malicious code on the server by sending a specially crafted data restoration command. This could lead to a complete takeover of the database server, potentially resulting in data theft or service disruption.
Technical details
A double-free vulnerability (CWE-415) exists in Redis versions prior to 8.8.0 due to an incomplete fix for a previous issue. The flaw is located in the stream data structure handling, specifically within the rdbLoadObject function. When a RESTORE command is executed with a payload where a single Pending Acknowledgment (NACK) is referenced by multiple consumers, deleting those consumers via XGROUP DELCONSUMER triggers a double free of the streamNACK object. An authenticated attacker can leverage this to achieve remote code execution. The vulnerability was reportedly discovered and exploited by an AI agent (Kimi K3). Users should upgrade to Redis 8.8.0 or later to resolve this issue.
Affected products
- Redis Redis before 8.8.0
Timeline
- 2026-04-23: patched: Fix merged into Redis unstable branch via PR 15081
- 2026-07-22: disclosed: Public disclosure of AI-discovered exploit on social media
- 2026-07-25: advisory: CVE-2026-66373 published