If you believe you've discovered a security vulnerability, please contact the Valkey team at security@lists.valkey.io. Please DO NOT create an issue. We follow a responsible disclosure procedure, so depending on the severity of the issue we may notify Valkey vendors about the issue before releasing it publicly. If you would like to be added to our list of vendors, please reach out to the Valkey team at maintainers@lists.valkey.io.
Security: valkey-io/valkey
Security
SECURITY.md
-
Use-after-free in the RDMA pending-data handler when a clientGHSA-jcj7-v34w-v9vv published
Aug 31, 2026 by madolsonHigh -
Unauthenticated use-after-free of the Lua interpreter state in Valkey (script debugger command cache)GHSA-fq2f-crmw-q97r published
Aug 31, 2026 by madolsonHigh -
UAF in stream deserialization may lead to remote code executionGHSA-mvcj-73cw-22m4 published
Jul 22, 2026 by madolsonHigh -
UAF in Valkey with TLS may lead to remote code executionGHSA-53mc-f3m3-99vh published
Jul 22, 2026 by madolsonHigh -
Pre-Authentication DOS from malformed RESP requestGHSA-93p9-5vc7-8wgr published
Feb 23, 2026 by madolsonHigh -
Remote DoS with malformed Valkey Cluster bus messageGHSA-c677-q3wr-gggq published
Feb 23, 2026 by madolsonModerate -
RESP Protocol Injection via Lua error_replyGHSA-p876-p7q5-hv2m published
Feb 23, 2026 by madolsonHigh -
Lua Use-After-Free may lead to remote code executionGHSA-9rfg-jx7v-52p6 published
Oct 3, 2025 by madolsonHigh -
DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated clientGHSA-24vm-hv6g-2mj5 published
Apr 28, 2025 by madolsonHigh -
Denial-of-service due to unbounded pattern matchingGHSA-p4rf-xgfj-c2gq published
Nov 11, 2024 by madolsonModerate
Learn more about advisories related to valkey-io/valkey in the GitHub Advisory Database