cbcvebase.
CVE-2026-21863
published 2026-02-23

CVE-2026-21863: Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can…

PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.55%
42.3th percentile
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianredict< valkey 8.1.4+dfsg1-2 (forky)valkey 8.1.4+dfsg1-2 (forky)
debianredis< valkey 8.1.4+dfsg1-2 (forky)valkey 8.1.4+dfsg1-2 (forky)
debianvalkey< valkey 8.1.4+dfsg1-2 (forky)valkey 8.1.4+dfsg1-2 (forky)
lfprojectsvalkey< 7.2.127.2.12
lfprojectsvalkey>= 0 < 8.1.1+dfsg1-3+deb13u28.1.1+dfsg1-3+deb13u2
lfprojectsvalkey>= 0 < 8.1.4+dfsg1-28.1.4+dfsg1-2
lfprojectsvalkey>= 0 < 7.2.12+dfsg1-0ubuntu0.17.2.12+dfsg1-0ubuntu0.1
lfprojectsvalkey>= 0 < 8.1.6+dfsg1-0ubuntu0.18.1.6+dfsg1-0ubuntu0.1
lfprojectsvalkey>= 8.0.0 < 8.0.78.0.7
lfprojectsvalkey>= 8.1.0 < 8.1.68.1.6
lfprojectsvalkey>= 9.0.0 < 9.0.29.0.2
msrcazl3_valkey_8.0.6-1_on_azure_linux_3.0
valkey-iovalkey< 7.2.127.2.12
valkey-iovalkey
valkey-iovalkey
valkey-iovalkey

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu8.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.