{"api_version":"1","generated_at":"2026-09-03T23:34:32+00:00","cve":"CVE-2026-63639","urls":{"html":"https://cve.report/CVE-2026-63639","api":"https://cve.report/api/cve/CVE-2026-63639.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-63639","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-63639"},"summary":{"title":"Valkey: UAF in stream deserialization may lead to remote code execution","description":"Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-08-18 15:16:56","updated_at":"2026-08-20 19:16:57"},"problem_types":["CWE-416","CWE-416 CWE-416: Use After Free"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://github.com/valkey-io/valkey/releases/tag/8.0.10","name":"https://github.com/valkey-io/valkey/releases/tag/8.0.10","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/valkey-io/valkey/releases/tag/7.2.14","name":"https://github.com/valkey-io/valkey/releases/tag/7.2.14","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/valkey-io/valkey/pull/4073","name":"https://github.com/valkey-io/valkey/pull/4073","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/valkey-io/valkey/security/advisories/GHSA-mvcj-73cw-22m4","name":"https://github.com/valkey-io/valkey/security/advisories/GHSA-mvcj-73cw-22m4","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/valkey-io/valkey/releases/tag/9.1.1","name":"https://github.com/valkey-io/valkey/releases/tag/9.1.1","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/valkey-io/valkey/commit/f8d2027e8d4df790ac04974bf606408c8ea62778","name":"https://github.com/valkey-io/valkey/commit/f8d2027e8d4df790ac04974bf606408c8ea62778","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/valkey-io/valkey/commit/06bc7768fe609f2054e69ccedefe7628f5675da9","name":"https://github.com/valkey-io/valkey/commit/06bc7768fe609f2054e69ccedefe7628f5675da9","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/valkey-io/valkey/commit/98465eaffe3f95524a5046318bfbc4bdb9798291","name":"https://github.com/valkey-io/valkey/commit/98465eaffe3f95524a5046318bfbc4bdb9798291","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/valkey-io/valkey/commit/509cb3c74e8cbc9c0498ebe8b6c93dcd605e7271","name":"https://github.com/valkey-io/valkey/commit/509cb3c74e8cbc9c0498ebe8b6c93dcd605e7271","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/valkey-io/valkey/releases/tag/9.0.5","name":"https://github.com/valkey-io/valkey/releases/tag/9.0.5","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/valkey-io/valkey/commit/e95911d4d65be8789fa3705f44d7ed1e65378445","name":"https://github.com/valkey-io/valkey/commit/e95911d4d65be8789fa3705f44d7ed1e65378445","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/valkey-io/valkey/releases/tag/8.1.9","name":"https://github.com/valkey-io/valkey/releases/tag/8.1.9","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-63639","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63639","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"valkey-io","product":"valkey","version":"affected < 7.2.14","platforms":[]},{"source":"CNA","vendor":"valkey-io","product":"valkey","version":"affected >= 8.0.0, < 8.0.10","platforms":[]},{"source":"CNA","vendor":"valkey-io","product":"valkey","version":"affected >= 8.1.0, < 8.1.9","platforms":[]},{"source":"CNA","vendor":"valkey-io","product":"valkey","version":"affected >= 9.0.0, < 9.0.5","platforms":[]},{"source":"CNA","vendor":"valkey-io","product":"valkey","version":"affected >= 9.1.0, < 9.1.1","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"63639","cve":"CVE-2026-63639","epss":"0.011710000","percentile":"0.645860000","score_date":"2026-08-23","updated_at":"2026-08-24 00:11:17"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-63639","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-08-19T03:56:16.213417Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-20T18:36:40.745Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"valkey","vendor":"valkey-io","versions":[{"status":"affected","version":"< 7.2.14"},{"status":"affected","version":">= 8.0.0, < 8.0.10"},{"status":"affected","version":">= 8.1.0, < 8.1.9"},{"status":"affected","version":">= 9.0.0, < 9.0.5"},{"status":"affected","version":">= 9.1.0, < 9.1.1"}]}],"descriptions":[{"lang":"en","value":"Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-416","description":"CWE-416: Use After Free","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-18T14:23:52.508Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/valkey-io/valkey/security/advisories/GHSA-mvcj-73cw-22m4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/valkey-io/valkey/security/advisories/GHSA-mvcj-73cw-22m4"},{"name":"https://github.com/valkey-io/valkey/pull/4073","tags":["x_refsource_MISC"],"url":"https://github.com/valkey-io/valkey/pull/4073"},{"name":"https://github.com/valkey-io/valkey/commit/06bc7768fe609f2054e69ccedefe7628f5675da9","tags":["x_refsource_MISC"],"url":"https://github.com/valkey-io/valkey/commit/06bc7768fe609f2054e69ccedefe7628f5675da9"},{"name":"https://github.com/valkey-io/valkey/commit/509cb3c74e8cbc9c0498ebe8b6c93dcd605e7271","tags":["x_refsource_MISC"],"url":"https://github.com/valkey-io/valkey/commit/509cb3c74e8cbc9c0498ebe8b6c93dcd605e7271"},{"name":"https://github.com/valkey-io/valkey/commit/98465eaffe3f95524a5046318bfbc4bdb9798291","tags":["x_refsource_MISC"],"url":"https://github.com/valkey-io/valkey/commit/98465eaffe3f95524a5046318bfbc4bdb9798291"},{"name":"https://github.com/valkey-io/valkey/commit/e95911d4d65be8789fa3705f44d7ed1e65378445","tags":["x_refsource_MISC"],"url":"https://github.com/valkey-io/valkey/commit/e95911d4d65be8789fa3705f44d7ed1e65378445"},{"name":"https://github.com/valkey-io/valkey/commit/f8d2027e8d4df790ac04974bf606408c8ea62778","tags":["x_refsource_MISC"],"url":"https://github.com/valkey-io/valkey/commit/f8d2027e8d4df790ac04974bf606408c8ea62778"},{"name":"https://github.com/valkey-io/valkey/releases/tag/7.2.14","tags":["x_refsource_MISC"],"url":"https://github.com/valkey-io/valkey/releases/tag/7.2.14"},{"name":"https://github.com/valkey-io/valkey/releases/tag/8.0.10","tags":["x_refsource_MISC"],"url":"https://github.com/valkey-io/valkey/releases/tag/8.0.10"},{"name":"https://github.com/valkey-io/valkey/releases/tag/8.1.9","tags":["x_refsource_MISC"],"url":"https://github.com/valkey-io/valkey/releases/tag/8.1.9"},{"name":"https://github.com/valkey-io/valkey/releases/tag/9.0.5","tags":["x_refsource_MISC"],"url":"https://github.com/valkey-io/valkey/releases/tag/9.0.5"},{"name":"https://github.com/valkey-io/valkey/releases/tag/9.1.1","tags":["x_refsource_MISC"],"url":"https://github.com/valkey-io/valkey/releases/tag/9.1.1"}],"source":{"advisory":"GHSA-mvcj-73cw-22m4","discovery":"UNKNOWN"},"title":"Valkey: UAF in stream deserialization may lead to remote code execution"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-63639","datePublished":"2026-08-18T14:23:52.508Z","dateReserved":"2026-07-17T14:11:15.482Z","dateUpdated":"2026-08-20T18:36:40.745Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-18 15:16:56","lastModifiedDate":"2026-08-20 19:16:57","problem_types":["CWE-416","CWE-416 CWE-416: Use After Free"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-19T03:56:16.213417Z","id":"CVE-2026-63639","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"63639","Ordinal":"1","Title":"Valkey: UAF in stream deserialization may lead to remote code ex","CVE":"CVE-2026-63639","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"63639","Ordinal":"1","NoteData":"Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.","Type":"Description","Title":"Valkey: UAF in stream deserialization may lead to remote code ex"}]}}}