✓ No known CVEs patched
This release patches 2 known CVEs
Topics
cache
database
key-value
key-value-store
nosql
redis
+2 more
valkey
valkey-client
Affected surfaces
rce_ssrf
auth
Summary
AI summaryUpdates Bug Fixes, Security Fixes, and CVE-2026-56684 across a mixed release.
Full changelog
Valkey 9.1.1 - Released Tue 21 July 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security Fixes
- CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
- CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
- Omit the implicit
alldbsACL rule fromACL LIST,ACL SAVEandCONFIG REWRITEso older versions can parse the output by @dvkashapov (#3964) - Improve throughput when IO threads are enabled by offloading object deallocation from the main thread by @roshkhatri (#3938)
- Fix use-after-free crash when
ACL LOADremoves a user whose authenticated client has its close deferred by @ranshid (#3800) - Enforce
db=ACL permissions on every DB clause ofCOPY, closing a bypass withREPLACEor repeated DB tokens by @enjoy-binbin (#3801) - Enforce database-level ACLs for
CLUSTER FLUSHSLOT, which removes keys from all databases by @enjoy-binbin (#3806) - Fix use-after-free in the module API when unregistering the first registered cluster message receiver by @eifrah-aws (#3846)
- Fix
HRANDFIELDwith a positive count looping forever when non-expired fields are fewer than the requested count by @cjx-zar (#4047) - Fix clients left on the wrong database after module keyspace notifications for
MOVEandCOPYby @enjoy-binbin (#4024) - Fix Sentinel crash during coordinated failover when the command link to the old primary disconnects by @lukepalmer (#4068)
- Fix crash when active hash field expiration leaves a single-entry expiry bucket whose last field is later removed by @ranshid (#3950)
- Fix assertion in
HEXPIRE,HGETDELandHPERSISTwhen a module blocks the client in a keyspace notification callback by @enjoy-binbin (#3743) - Fix undefined behavior in the failover delay calculation when
cluster-node-timeoutis below 30 milliseconds by @enjoy-binbin (#3941) - Reject zipmap RESTORE/RDB payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
- Reject NAN scores in listpack and ziplist encoded sorted sets on RDB/RESTORE load, preventing a crash on skiplist conversion by @madolson (#3921)
- Fix corrupted replies (dropped leading bytes) caused by a reply buffer race when IO threads are enabled by @nanyan0312 (#4060)
- Fix startup crash on 32-bit systems where time_t is 64-bit (such as Alpine 3.23) when generating
INFOoutput by @chenshi5012 (#3787) HGETDELnow returns a syntax error when theFIELDSkeyword is missing or misplaced by @lcxn123 (#4049)COMMAND INFOin RESP3 now returns the subcommands field as an array instead of a set for commands without subcommands by @rickrams (#3939)- Send the replica version on the dual-channel RDB connection so full syncs with newer encodings like hash field TTLs succeed by @hpatro (#4105)
- Fix duplicate failure handling and an invalid reply sequence in cluster slot migration by @chx9 (#3723)
- Reject control characters in
SENTINEL SETvalues to prevent config-file injection via Sentinel config rewrite by @eifrah-aws (#3847) - Reject control characters and delimiters in cluster AUX fields and validate
cluster-announce-ipto prevent nodes.conf injection by @eifrah-aws (#3848) - Redact key names and user data from more server log messages when
hide-user-data-from-logis enabled by @zackcam (#3872) ACL LOGnow reports the denied database ID forCOPYinstead of the command name whendb=access is denied by @enjoy-binbin (#3888)- Fix garbled shard IDs in the cluster UPDATE message log line by @enjoy-binbin (#3942)
- Fix negative
master_sync_total_bytesinINFO replicationduring disk-based sync when the RDB exceeds 2GB by @chx9 (#3811) - Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long paths by @pkhartsk (#3843)
Full Changelog: https://github.com/valkey-io/valkey/compare/9.1.0...9.1.1
Security Fixes
- CVE-2026-56684 — Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL
- CVE-2026-63639 — Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About valkey
A flexible distributed key-value database that is optimized for caching and other realtime workloads.
Related context
Related tools
Beta — feedback welcome: [email protected]