Threat reportVulnerabilityTL-2026-0682
Redis RCE CVE-2026-23479 — Use-After-Free in unblockClientOnKey() (Authenticated, CVSS 8.8)
Redis RCE CVE-2026-23479 (TL-2026-0682) is a high-severity software vulnerability scored CVSS 8.8, first published 2026-06-04. It has no confirmed attribution, affects Redis Redis CE/OSS, references 1 CVE (CVE-2026-23479), maps to 8 MITRE ATT&CK techniques (T1059, T1059.004, T1068), and is covered by 9 detection rules and 12 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 8MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-0682
- Threat ID
- TL-2026-0682
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, financial, ecommerce, saas, gaming, telecommunications
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 12
How Redis RCE CVE-2026-23479 works
An authenticated use-after-free (CWE-416) in Redis's unblock-client flow (unblockClientOnKey() in src/blocked.c) enables heap corruption that chains to remote code execution as the redis-server process. Surfaced after 2+ years by Theori's autonomous Xint Code AI tool at ZeroDay.Cloud 2025 and reported by Team Xint Code; a full 3-stage exploit write-up (heap leak -> heap reclaim -> GOT overwrite) is now public.
CVE-2026-23479 is a use-after-free vulnerability in the Redis blocked-client wake-up path. unblockClientOnKey() dispatches a queued, previously-blocked command through processCommandAndResetClient() and then continues to dereference the same client pointer. The function header explicitly warns that the client may be freed as a side effect of processing the command, yet the return value is ignored. The defect was introduced by two separate changes: PR #11012 (January 2023) added the unchecked processCommandAndResetClient() call, and PR #11568 (March 2023) added further client access after that call. It shipped in Redis 7.2.0 (late 2023) and survived multiple security review rounds across every stable branch through 8.6.2 for over two years.
Exploitation is a three-stage chain. Stage 1 (information leak): an authenticated attacker runs the Lua one-liner EVAL "return tostring(redis.call)" 0, which returns a function pointer exposing a stable Redis heap address used to populate fake-client fields. Stage 2 (UAF trigger and reclaim): the attacker grooms memory via CONFIG SET maxmemory-clients and client-output-buffer-limit, parks a bloated client blocked on a stream (XREAD BLOCK 0), then on a second connection lowers maxmemory-clients to 1 and issues XADD to wake the blocked client. The wake-up frees the blocked client during eviction, but unblockClientOnKey() keeps using the dangling pointer (zfree() does not zero memory) and queueClientForReprocessing() re-appends the freed pointer to server.unblocked_clients for same-iteration processing. A pipelined SET reclaim:<rand> <fake-client-bytes> reclaims the freed slot with an attacker-crafted client structure (controlled last_memory_type as an OOB index, last_memory_usage as a decrement, CLIENT_PENDING_COMMAND flag set, and leaked heap pointers to avoid crashes). Stage 3 (RCE): when Redis drains server.unblocked_clients it processes the reclaimed allocation via updateClientMemoryUsage(), executing server.stat_clients_type_memory[c->last_memory_type] -= c->last_memory_usage as an out-of-bounds write. With partial RELRO (default in official Redis Docker images) the .got.plt is writable, so the attacker corrupts the GOT entry for strcasecmp to point at system(). The next command parsed invokes strcasecmp() and instead runs the command string as a shell command with redis-server privileges.
The exploit requires post-authentication access with ACL categories @admin (CONFIG SET), @scripting (EVAL), @stream (XREAD/XADD), and @read/@write (SET/GET) — all granted to the default user in standard deployments. Redis reports no in-the-wild exploitation as of the 2026-05-05 advisory, but the complete technical chain is now public, elevating follow-on risk for internet-exposed or weakly-segmented instances.
MITRE ATT&CK techniques used in TL-2026-0682
Execution
T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter: Unix Shell; T1106 Native API
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Discovery
T1082 System Information Discovery
Initial Access
T1190 Exploit Public-Facing Application
Defense Evasion
T1211 Exploitation for Stealth
Impact
T1499.004 Endpoint Denial of Service: Application or System Exploitation
Affected products and versions in Redis RCE CVE-2026-23479
- Redis — Redis CE/OSS
Vulnerable versions: 7.2.0-7.2.13; 7.4.0-7.4.8; 8.2.0-8.2.5; 8.4.0-8.4.2; 8.6.0-8.6.2
Fixed in: 6.2.22; 7.2.14; 7.4.9; 8.2.6; 8.4.3; 8.6.3 - Redis — Redis Software (Enterprise)
Vulnerable versions: <= 8.0.6
Fixed in: 8.0.10-64; 7.22.2-79; 7.8.6-253; 7.4.6-279; 7.2.4-153 - Redis — Redis Cloud
Vulnerable versions: pre-2026-05-05
Fixed in: Auto-patched by Redis as of 2026-05-05
Remediation for Redis RCE CVE-2026-23479
Patches
- Redis CE/OSS 6.2.22 / 7.2.14 / 7.4.9 / 8.2.6 / 8.4.3 / 8.6.3
- Redis Software 8.0.10-64 / 7.22.2-79 / 7.8.6-253 / 7.4.6-279 / 7.2.4-153
Immediate actions
- Upgrade Redis CE/OSS to a fixed release: 6.2.22, 7.2.14, 7.4.9, 8.2.6, 8.4.3, or 8.6.3
- For Redis Software upgrade to 8.0.10-64, 7.22.2-79, 7.8.6-253, 7.4.6-279, or 7.2.4-153
- Restrict Redis network access to private subnets; block 6379/tcp at the perimeter and require TLS
- Remove @admin, CONFIG, and @scripting from non-administrative ACL roles; disable scripting if unused
- Rotate broadly-distributed Redis credentials
Workarounds
- ACL: deny EVAL/EVALSHA, CONFIG, XADD/XREAD, and maxmemory-clients changes to application users
- Run redis-server as an unprivileged, sandboxed user with no outbound network egress
- Front Redis with an authenticating proxy and IP allowlist
Longer-term hardening
- Enforce least-privilege ACLs per application identity
- Enable protected-mode on CE/OSS deployments
- Deploy host/EDR monitoring for redis-server spawning child shells
- Subscribe to Redis security advisories and patch on a defined SLA
CVEs associated with Redis RCE CVE-2026-23479
Weaknesses (CWE) in Redis RCE CVE-2026-23479
Timeline of Redis RCE CVE-2026-23479
- Redis PR #11012 adds an unchecked call to processCommandAndResetClient() in the unblock-client flow.
- Redis PR #11568 adds further client-pointer access after the unchecked call, completing the use-after-free condition.
- Vulnerable code ships in Redis 7.2.0 and propagates to every stable branch through 8.6.2.
- Theori's autonomous Xint Code AI tool surfaces the UAF in src/blocked.c during the ZeroDay.Cloud 2025 competition in London.
- Redis publishes the security advisory and fixed releases (6.2.22/7.2.14/7.4.9/8.2.6/8.4.3/8.6.3); Redis Cloud auto-patched. No ITW exploitation reported.
- The Hacker News reports the flaw and the ZeroDay.Cloud deep-dive publishes the full 3-stage exploit chain, making the technical details public.
Sources cited for Redis RCE CVE-2026-23479
- Redis Security Advisory — CVE-2026-23479 et al.
- Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)
- Redis CVE-2026-23479 Deep Dive — Full Exploit Chain
- NVD — CVE-2026-23479
- Redis PR #11012 — introduced unchecked processCommandAndResetClient() call
- Redis PR #11568 — added client access after the unchecked call
- MITRE CWE-416: Use After Free
Detection coverage for TL-2026-0682
As of 2026-06-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0682 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.