← Vulnerability feed

Vulnerability record · CVE-2026-21863 · published 23 February 2026

CVE-2026-21863: Lfprojects valkey out-of-bounds read vulnerability

Lfprojects · Valkey

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

7.5 CVSS 3.1 High EPSS 0.78% · top 46.0% CWE-125 · Out-of-bounds read
7.5CVSS 3.1 base score
0.78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
15 Jul 2026Last modified by NVD

Description

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21863 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2025-49844Redis Lua scripting use-after-free enables remote code executionRedis versions 8.2.1 and below contain a use-after-free in the Lua scripting engine. An authenticated user can supply a crafted Lua script that manip…EPSS 82%analysed7.5CVE-2026-27623Lfprojects valkey improper input validation vulnerabilityValkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can…EPSS 0.65%7.5CVE-2025-21605Redis allocation without limits vulnerabilityRedis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An unauthenticated client can caus…EPSS 0.86%7.1CVE-2025-67733Lfprojects valkey injection vulnerabilityValkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject …EPSS 0.60%8.8CVE-2026-11645Google Chrome V8 out-of-bounds read and write enables sandbox code executionGoogle Chrome before 149.0.7827.103 contains an out-of-bounds read and write in the V8 JavaScript engine. A crafted HTML page can trigger the memory …KEVEPSS 2.2%analysed7.8CVE-2023-36424Windows Common Log File System Driver out-of-bounds read privilege escalationCVE-2023-36424 is an out-of-bounds read (CWE-125) in the Windows Common Log File System (CLFS) driver that allows elevation of privilege. It affects …KEVEPSS 12%analysed9.3CVE-2026-3055Citrix NetScaler ADC and Gateway SAML IDP memory overreadNetScaler ADC and NetScaler Gateway, when configured as a SAML identity provider, fail to validate input sufficiently, causing an out-of-bounds memor…KEVEPSS 4.0%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2026-21863), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.