Release history
valkey releases
A flexible distributed key-value database that is optimized for caching and other realtime workloads.
All releases
12 shown
- CVE-2026-23479 — Use‑After‑Free in unblock client flow
- CVE-2026-25243 — Invalid Memory Access in RESTORE command
- CVE-2026-23631 — Use‑after‑free when full sync occurs during a yielding Lua/function execution
Full changelog
Upgrade urgency SECURITY: This release includes security fixes we recommend you
apply as soon as possible.
Security fixes
- (CVE-2026-23479) Use-After-Free in unblock client flow
- (CVE-2026-25243) Invalid Memory Access in RESTORE command
- (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution
- CVE-2026-23479 – Use‑After‑Free in unblock client flow
- CVE-2026-25243 – Invalid Memory Access in RESTORE command
- CVE-2026-23631 – Use‑after‑free when full sync occurs during yielding Lua/function execution
Full changelog
Upgrade urgency SECURITY: This release includes security fixes we recommend you
apply as soon as possible.
Security fixes
- (CVE-2026-23479) Use-After-Free in unblock client flow
- (CVE-2026-25243) Invalid Memory Access in RESTORE command
- (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution
- CVE-2026-23479 — Use-After-Free in unblock client flow
- CVE-2026-25243 — Invalid Memory Access in RESTORE command
- CVE-2026-23631 — Use-after-free when full sync occurs during yielding Lua/function execution
Full changelog
Upgrade urgency SECURITY: This release includes security fixes we recommend you
apply as soon as possible.
Security fixes
- (CVE-2026-23479) Use-After-Free in unblock client flow
- (CVE-2026-25243) Invalid Memory Access in RESTORE command
- (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution
- CVE-2026-23479 — Use‑After‑Free in unblock client flow
- CVE-2026-25243 — Invalid Memory Access in RESTORE command
- CVE-2026-23631 — Use‑after‑free when full sync occurs during yielding Lua/function execution
Full changelog
Upgrade urgency SECURITY: This release includes security fixes we recommend you
apply as soon as possible.
Security fixes
- (CVE-2026-23479) Use-After-Free in unblock client flow
- (CVE-2026-25243) Invalid Memory Access in RESTORE command
- (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution
- CVE-2025-67733 RESP Protocol Injection via Lua error_reply
- CVE-2026-21863 Remote DoS with malformed cluster bus message
- CVE-2026-27623 Reset request type after handling empty requests
- CVE-2026-21863 Remote DoS with malformed cluster bus message
- CVE-2025-67733 RESP Protocol Injection via Lua error_reply
- CVE-2026-21863 Remote DoS with malformed cluster bus message
- CVE-2025-67733 RESP Protocol Injection via Lua error_reply
- CVE-2026-21863 Remote DoS with malformed cluster bus message
- CVE-2025-67733 RESP Protocol Injection via Lua error_reply
Critical bug fixes for hash field expiration memory leaks and numerous hash operation corrections including HINCRBY tracking