CyberRota Analysis
Bellek tüketimine neden olabilir. Uzaktan istismar edilebilir olabilir.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Detected Signals
remote code execution code execution
GitHub PoC Links
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2026-23479
Severity
HIGH
CVSS
8.8
EPSS
0.10%
Original NVD Description
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.