Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
PoC: CVE-2026-23479
Redis CVE-2026-23479 UAF RCE vulnerability checker mirror — pduggusa, MIT; for authorized security testing
[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-23479-Redis-UAF-Proof-of-Concept
Proof of concept with GDB‑assisted exploitation (educational / lab use only)
[POC] CVE-2026-23479 — redis-cve-2026-23479-scanner
CVE-2026-23479 Redis Use-After-Free vulnerability detection tool
[POC] CVE-2026-23479 — redis-cve-2026-23479-check
Safe read-only version checker + Sigma rule for Redis CVE-2026-23479 (authenticated use-after-free → RCE). Find exposed instances, patch left-of-boom. By DugganUSA.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free