Threat reportVulnerabilityTL-2026-0713

Redis DarkReplica (CVE-2026-23631) — Post-Auth RCE via Lua Functions-Engine Use-After-Free During Master-Replica Sync

highPATCHED

Redis DarkReplica (CVE-2026-23631) (TL-2026-0713), also tracked as DarkReplica, is a high-severity software vulnerability scored CVSS 8.1, first published 2026-06-08. It has no confirmed attribution, affects Redis redis-server, references 1 CVE (CVE-2026-23631), maps to 12 MITRE ATT&CK techniques (T1059, T1068, T1082), and is covered by 9 detection rules and 12 indicators of compromise.

CVSS
8.1/10High
CVEs
1Referenced vulnerabilities
Techniques
12MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
12Indicators of compromise

Key facts for TL-2026-0713

Threat ID
TL-2026-0713
Also known as
DarkReplica, GHSA-8ghh-qpmp-7826
Severity
HIGH
CVSS
8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, financial, e-commerce, cloud, saas, gaming, telecommunications
Target regions
Global
Detection rules
9
Indicators of compromise
12

Malware and tooling in Redis DarkReplica (CVE-2026-23631)

Malware and tooling: Attacker-controlled rogue Redis master serving malicious RDB

How Redis DarkReplica (CVE-2026-23631) works

DarkReplica (CVE-2026-23631) is a post-authentication remote code execution flaw in Redis. An authenticated attacker issues SLAVEOF/REPLICAOF to make a target instance replicate an attacker-controlled rogue master; during sync the replica loads a new Lua function context from the incoming RDB while a paused (yielded) Lua function is allowed to resume on a now-freed lua_State, producing a use-after-free (CWE-416) that researchers chained into read/write primitives and full RCE on the host. Patched by Redis on May 5, 2026 (fixed in 8.6.3 and backported series).

DarkReplica is a critical-impact, post-authentication remote code execution vulnerability (CVE-2026-23631, GHSA-8ghh-qpmp-7826) in the Redis server's Lua functions engine, exposed through the master-replica synchronization path. It was discovered by independent researcher Yoni Sherez during the Wiz ZeroDay.Cloud 2025 event and disclosed/patched by Redis on May 5, 2026.

Redis ships two server-side Lua engines that let administrators run custom logic inside the database: the legacy scripting engine (EVAL/EVALSHA) and the newer functions engine (FUNCTION LOAD/FCALL). To keep the single-threaded server responsive, Redis handles long-running Lua by periodically yielding control back to the event loop so it can process other events — this cooperative yielding is also what makes FUNCTION KILL able to terminate a slow script. DarkReplica abuses the interaction between this yield mechanism and replication.

An attacker who can authenticate to a Redis instance instructs that instance to become a replica of an attacker-controlled master using SLAVEOF (alias REPLICAOF). The bug is reachable only on replicas where `replica-read-only` is disabled, or can be disabled, and exists in all Redis versions with Lua scripting. When the replica performs full synchronization it loads a fresh function context from the incoming RDB (Redis dump) file the rogue master serves. The replication handler frees the currently running Lua engine and installs the new context — but it does not prevent a paused/yielded Lua function from resuming. The paused function then continues executing against its freed lua_State and related objects, yielding a use-after-free.

Exploitation is complex but practical. The researchers built primitives to leak heap addresses, force deterministic heap allocations, and craft fake Lua objects. By running the vulnerable code inside Lua coroutines and carefully spraying the Lua memory arena, they regained control of the Lua VM and obtained arbitrary read/write primitives. From there they redirected internal Lua function pointers to libc functions and invoked system commands, achieving full remote code execution on the host under the Redis service account.

The NVD primary CVSS v3.1 base score is 8.1 (HIGH, AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H); GitHub's secondary CVSS v4.0 score is 6.1 (MEDIUM, AC:H reflecting exploitation complexity). The integrity and availability impact is HIGH (code execution, full host control) with no direct confidentiality vector scored, though host RCE trivially exposes all data. The precondition — valid credentials plus advanced memory-corruption tradecraft — bounds mass exploitation, but the risk is acute for internet-exposed or weakly-authenticated Redis deployments and for any environment where an attacker can obtain valid credentials or where replicas run with replica-read-only disabled. The flaw is distinct from prior Redis threats tracked on the platform (CVE-2026-23479 / TL-2026-0682 and P2Pinfect / TL-2026-0537).

Defenders should upgrade to fixed releases immediately (8.6.3 and the backported 7.2.x / 7.4.x / 8.2.x / 8.4.x / 8.6.x fixes published May 5, 2026), enforce strong authentication and ACLs, restrict the SLAVEOF/REPLICAOF and Lua command surface via ACL, keep `replica-read-only` enabled, and isolate Redis from untrusted networks. Where patching is not immediately possible, the vendor workaround is to prevent users from executing Lua scripts or avoid replicas with replica-read-only disabled.

MITRE ATT&CK techniques used in TL-2026-0713

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Discovery

T1082 System Information Discovery

Credential Access

T1110 Brute Force

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Defense Evasion

T1211 Exploitation for Stealth

Impact

T1565 Data Manipulation

Reconnaissance

T1595 Active Scanning

Resource Development

T1608 Stage Capabilities

Affected products and versions in Redis DarkReplica (CVE-2026-23631)

  • Redis — redis-server
    Vulnerable versions: all versions with Lua scripting prior to fixed releases; 7.2.x < fixed; 7.4.x < fixed; 8.2.x < fixed; 8.4.x < fixed; 8.6.x < 8.6.3
    Fixed in: 8.6.3; 7.2.x (2026-05-05); 7.4.x (2026-05-05); 8.2.x (2026-05-05); 8.4.x (2026-05-05); 8.6.x (2026-05-05)

Remediation for Redis DarkReplica (CVE-2026-23631)

Patches

  • Redis 8.6.3 (primary fix)
  • Backported fixes in 7.2.x, 7.4.x, 8.2.x, 8.4.x, 8.6.x series (released 2026-05-05)

Immediate actions

  • Upgrade Redis to a fixed release immediately: 8.6.3 or the backported fixes across 7.2.x / 7.4.x / 8.2.x / 8.4.x / 8.6.x published 2026-05-05
  • Audit all internet-exposed and internal Redis instances; remove direct network exposure and bind to trusted interfaces only
  • Enforce strong authentication (requirepass / ACL users) and rotate any weak or shared Redis credentials

Workarounds

  • Prevent users from executing Lua scripts (restrict EVAL/FUNCTION via ACL)
  • Avoid using replicas where replica-read-only is disabled

Longer-term hardening

  • Keep replica-read-only enabled on all replicas and forbid disabling it via configuration management
  • Restrict the Lua command surface (EVAL/EVALSHA/FUNCTION/FCALL) and replication commands (SLAVEOF/REPLICAOF) using Redis ACL category and command rules for non-admin users
  • Deploy network segmentation so Redis cannot initiate outbound replication to untrusted/attacker-controlled masters
  • Monitor for unexpected REPLICAOF/SLAVEOF reconfiguration and unexpected changes to functions/scripts

CVEs associated with Redis DarkReplica (CVE-2026-23631)

CVE-2026-23631

Weaknesses (CWE) in Redis DarkReplica (CVE-2026-23631)

CWE-416

Timeline of Redis DarkReplica (CVE-2026-23631)

  • DarkReplica use-after-free discovered by independent researcher Yoni Sherez during the Wiz ZeroDay.Cloud 2025 research event.
  • Redis releases 8.6.3 along with backported fixes across the 7.2.x, 7.4.x, 8.2.x, 8.4.x, and 8.6.x maintained series.
  • Redis publishes security advisory GHSA-8ghh-qpmp-7826 and assigns CVE-2026-23631 for the Lua functions-engine use-after-free during replication.
  • NVD assigns primary CVSS v3.1 base score 8.1 (HIGH) and CWE-416; GitHub secondary CVSS v4.0 base score 6.1 (MEDIUM).
  • Threadlinqs Intelligence opens TL-2026-0713 to track DarkReplica with detection and simulation coverage.
  • Public technical write-up describing the full exploitation chain (heap leak, fake Lua objects, coroutine-driven UAF, libc redirection to RCE) published by Cyber Security News.

Sources cited for Redis DarkReplica (CVE-2026-23631)

Detection coverage for TL-2026-0713

As of 2026-06-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0713 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
12 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats