{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-81934","assignerOrgId":"9119a7d8-5eab-497f-8521-727c672e3725","state":"PUBLISHED","assignerShortName":"cisa-cg","dateReserved":"2026-08-27T19:15:11.715Z","datePublished":"2026-08-27T19:40:15.141Z","dateUpdated":"2026-08-31T19:17:53.121Z"},"containers":{"cna":{"descriptions":[{"lang":"en","value":"Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server."}],"affected":[{"vendor":"Redis","product":"Redis","defaultStatus":"unknown","versions":[{"version":"8.2.9","status":"unaffected"},{"version":"8.4.6","status":"unaffected"},{"version":"8.6.6","status":"unaffected"},{"version":"8.8.2","status":"unaffected"},{"version":"8.10.1","status":"unaffected"},{"version":"7.4.11","status":"unaffected"},{"version":"6.2.24","status":"unaffected"},{"version":"7.2.16","status":"unaffected"},{"version":"0","status":"affected","lessThan":"8.8.2","versionType":"custom"},{"version":"0","status":"affected","lessThan":"8.2.9","versionType":"custom"},{"version":"0","status":"affected","lessThan":"8.4.6","versionType":"custom"},{"version":"0","status":"affected","lessThan":"8.6.6","versionType":"custom"},{"version":"0","status":"affected","lessThan":"8.10.1","versionType":"custom"},{"version":"0","status":"affected","lessThan":"7.4.11","versionType":"custom"},{"version":"0","status":"affected","lessThan":"6.2.24","versionType":"custom"},{"version":"0","status":"affected","lessThan":"7.2.16","versionType":"custom"}]},{"vendor":"Redis","product":"Redis Software (Enterprise)","defaultStatus":"unknown","versions":[{"version":"8.2.0-46","status":"unaffected"},{"version":"8.0.20-96","status":"unaffected"},{"version":"7.22.2-179","status":"unaffected"},{"version":"7.8.6-303","status":"unaffected"},{"version":"0","status":"affected","lessThan":"8.2.0-46","versionType":"custom"},{"version":"0","status":"affected","lessThan":"8.0.20-96","versionType":"custom"},{"version":"0","status":"affected","lessThan":"7.22.2-179","versionType":"custom"},{"version":"0","status":"affected","lessThan":"7.8.6-303","versionType":"custom"}]}],"problemTypes":[{"descriptions":[{"description":"CWE-416 Use After Free","lang":"en","type":"CWE","cweId":"CWE-416"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.1,"attackVector":"ADJACENT_NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"HIGH","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"HIGH"}},{"cvssV4_0":{"version":"4.0","baseScore":7.5,"attackVector":"ADJACENT","baseSeverity":"HIGH","vectorString":"CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","userInteraction":"NONE","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"LOW","subIntegrityImpact":"NONE","vulnIntegrityImpact":"HIGH","subAvailabilityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnConfidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-08-27T19:12:51.964039Z","id":"CVE-2026-81934","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"Redis TLS pending-data list use-after-free","references":[{"name":"url","url":"https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834","tags":["patch"]},{"name":"url","url":"https://github.com/v12-security/pocs/tree/main/redis/server_ssl","tags":["exploit"]},{"name":"url","url":"https://raw.githubusercontent.com/redis/redis/8.2/00-RELEASENOTES","tags":["release-notes"]},{"name":"url","url":"https://raw.githubusercontent.com/redis/redis/8.4/00-RELEASENOTES","tags":["release-notes"]},{"name":"url","url":"https://raw.githubusercontent.com/redis/redis/8.6/00-RELEASENOTES","tags":["release-notes"]},{"name":"url","url":"https://raw.githubusercontent.com/redis/redis/8.8/00-RELEASENOTES","tags":["release-notes"]},{"name":"url","url":"https://raw.githubusercontent.com/redis/redis/8.10/00-RELEASENOTES","tags":["release-notes"]},{"name":"url","url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-239-01.json","tags":["third-party-advisory"]},{"name":"url","url":"https://www.cve.org/CVERecord?id=CVE-2026-81934","tags":["vdb-entry"]},{"name":"url","url":"https://github.com/redis/redis/releases/tag/6.2.24","tags":["release-notes"]},{"name":"url","url":"https://github.com/redis/redis/releases/tag/7.2.16","tags":["release-notes"]},{"name":"url","url":"https://github.com/redis/redis/releases/tag/7.4.11","tags":["release-notes"]},{"name":"url","url":"https://github.com/redis/redis/releases/tag/8.4.6","tags":["release-notes"]},{"name":"url","url":"https://github.com/redis/redis/releases/tag/8.2.9","tags":["release-notes"]},{"name":"url","url":"https://github.com/redis/redis/releases/tag/8.6.6","tags":["release-notes"]},{"name":"url","url":"https://github.com/redis/redis/releases/tag/8.8.2","tags":["release-notes"]},{"name":"url","url":"https://github.com/redis/redis/releases/tag/8.10.1","tags":["release-notes"]},{"name":"url","url":"https://redis.io/docs/latest/operate/rs/release-notes/rs-8-2-releases/rs-8-2-0-46/","tags":["release-notes"]},{"name":"url","url":"https://redis.io/docs/latest/operate/rs/release-notes/rs-8-0-releases/rs-8-0-20-96/","tags":["release-notes"]},{"name":"url","url":"https://redis.io/docs/latest/operate/rs/release-notes/rs-7-22-releases/rs-7-22-2-179/","tags":["release-notes"]},{"name":"url","url":"https://redis.io/docs/latest/operate/rs/release-notes/rs-7-8-releases/rs-7-8-6-303/","tags":["release-notes"]},{"name":"url","url":"https://raw.githubusercontent.com/redis/redis/7.4/00-RELEASENOTES","tags":["release-notes"]},{"name":"url","url":"https://raw.githubusercontent.com/redis/redis/7.2/00-RELEASENOTES","tags":["release-notes"]},{"name":"url","url":"https://raw.githubusercontent.com/redis/redis/6.2/00-RELEASENOTES","tags":["release-notes"]}],"datePublic":"2026-08-17T00:00:00.000Z","providerMetadata":{"orgId":"9119a7d8-5eab-497f-8521-727c672e3725","shortName":"cisa-cg","dateUpdated":"2026-08-31T19:17:53.121Z"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-28T15:13:56.058373Z","id":"CVE-2026-81934","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-28T15:14:13.092Z"}}]}}