Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834 cve-icon cve-icon
https://github.com/redis/redis/releases/tag/6.2.24 cve-icon cve-icon
https://github.com/redis/redis/releases/tag/7.2.16 cve-icon cve-icon
https://github.com/redis/redis/releases/tag/7.4.11 cve-icon cve-icon
https://github.com/redis/redis/releases/tag/8.10.1 cve-icon cve-icon
https://github.com/redis/redis/releases/tag/8.2.9 cve-icon cve-icon
https://github.com/redis/redis/releases/tag/8.4.6 cve-icon cve-icon
https://github.com/redis/redis/releases/tag/8.6.6 cve-icon cve-icon
https://github.com/redis/redis/releases/tag/8.8.2 cve-icon cve-icon
https://github.com/v12-security/pocs/tree/main/redis/server_ssl cve-icon cve-icon
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-239-01.json cve-icon cve-icon
https://raw.githubusercontent.com/redis/redis/6.2/00-RELEASENOTES cve-icon cve-icon
https://raw.githubusercontent.com/redis/redis/7.2/00-RELEASENOTES cve-icon cve-icon
https://raw.githubusercontent.com/redis/redis/7.4/00-RELEASENOTES cve-icon cve-icon
https://raw.githubusercontent.com/redis/redis/8.10/00-RELEASENOTES cve-icon cve-icon
https://raw.githubusercontent.com/redis/redis/8.2/00-RELEASENOTES cve-icon cve-icon
https://raw.githubusercontent.com/redis/redis/8.4/00-RELEASENOTES cve-icon cve-icon
https://raw.githubusercontent.com/redis/redis/8.6/00-RELEASENOTES cve-icon cve-icon
https://raw.githubusercontent.com/redis/redis/8.8/00-RELEASENOTES cve-icon cve-icon
https://redis.io/docs/latest/operate/rs/release-notes/rs-7-22-releases/rs-7-22-2-179/ cve-icon cve-icon
https://redis.io/docs/latest/operate/rs/release-notes/rs-7-8-releases/rs-7-8-6-303/ cve-icon cve-icon
https://redis.io/docs/latest/operate/rs/release-notes/rs-8-0-releases/rs-8-0-20-96/ cve-icon cve-icon
https://redis.io/docs/latest/operate/rs/release-notes/rs-8-2-releases/rs-8-2-0-46/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-81934 cve-icon cve-icon
History

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1. Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Fri, 28 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Redis
Redis redis
Vendors & Products Redis
Redis redis

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.
Title Redis TLS pending-data list use-after-free
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-08-31T19:17:53.121Z

Reserved: 2026-08-27T19:15:11.715Z

Link: CVE-2026-81934

cve-icon Vulnrichment

Updated: 2026-08-28T15:14:03.738Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-27T20:18:57.350

Modified: 2026-08-31T20:17:12.093

Link: CVE-2026-81934

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T10:30:17Z

Weaknesses