# Redis DarkReplica (CVE-2026-23631) — Post-Auth RCE via Lua Functions-Engine Use-After-Free During Master-Replica Sync

> DarkReplica (CVE-2026-23631) is a post-authentication remote code execution flaw in Redis. An authenticated attacker issues SLAVEOF/REPLICAOF to make a target instance replicate an attacker-controlled rogue master; during sync the replica loads a new Lua function context from the incoming RDB while a paused (yielded) Lua function is allowed to resume on a now-freed lua_State, producing a use-after-free (CWE-416) that researchers chained into read/write primitives and full RCE on the host. Patched by Redis on May 5, 2026 (fixed in 8.6.3 and backported series).

- **Published:** 2026-06-08T00:00:00Z
- **Last reviewed:** 2026-06-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0713
- **ID:** TL-2026-0713
- **Severity:** HIGH (CVSS 8.1)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-23631

## Description

DarkReplica is a critical-impact, post-authentication remote code execution vulnerability (CVE-2026-23631, GHSA-8ghh-qpmp-7826) in the Redis server's Lua functions engine, exposed through the master-replica synchronization path. It was discovered by independent researcher Yoni Sherez during the Wiz ZeroDay.Cloud 2025 event and disclosed/patched by Redis on May 5, 2026.

Redis ships two server-side Lua engines that let administrators run custom logic inside the database: the legacy scripting engine (EVAL/EVALSHA) and the newer functions engine (FUNCTION LOAD/FCALL). To keep the single-threaded server responsive, Redis handles long-running Lua by periodically yielding control back to the event loop so it can process other events — this cooperative yielding is also what makes FUNCTION KILL able to terminate a slow script. DarkReplica abuses the interaction between this yield mechanism and replication.

An attacker who can authenticate to a Redis instance instructs that instance to become a replica of an attacker-controlled master using SLAVEOF (alias REPLICAOF). The bug is reachable only on replicas where `replica-read-only` is disabled, or can be disabled, and exists in all Redis versions with Lua scripting. When the replica performs full synchronization it loads a fresh function context from the incoming RDB (Redis dump) file the rogue master serves. The replication handler frees the currently running Lua engine and installs the new context — but it does not prevent a paused/yielded Lua function from resuming. The paused function then continues executing against its freed lua_State and related objects, yielding a use-after-free.

Exploitation is complex but practical. The researchers built primitives to leak heap addresses, force deterministic heap allocations, and craft fake Lua objects. By running the vulnerable code inside Lua coroutines and carefully spraying the Lua memory arena, they regained control of the Lua VM and obtained arbitrary read/write primitives. From there they redirected internal Lua function pointers to libc functions and invoked system commands, achieving full remote code execution on the host under the Redis service account.

The NVD primary CVSS v3.1 base score is 8.1 (HIGH, AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H); GitHub's secondary CVSS v4.0 score is 6.1 (MEDIUM, AC:H reflecting exploitation complexity). The integrity and availability impact is HIGH (code execution, full host control) with no direct confidentiality vector scored, though host RCE trivially exposes all data. The precondition — valid credentials plus advanced memory-corruption tradecraft — bounds mass exploitation, but the risk is acute for internet-exposed or weakly-authenticated Redis deployments and for any environment where an attacker can obtain valid credentials or where replicas run with replica-read-only disabled. The flaw is distinct from prior Redis threats tracked on the platform (CVE-2026-23479 / TL-2026-0682 and P2Pinfect / TL-2026-0537).

Defenders should upgrade to fixed releases immediately (8.6.3 and the backported 7.2.x / 7.4.x / 8.2.x / 8.4.x / 8.6.x fixes published May 5, 2026), enforce strong authentication and ACLs, restrict the SLAVEOF/REPLICAOF and Lua command surface via ACL, keep `replica-read-only` enabled, and isolate Redis from untrusted networks. Where patching is not immediately possible, the vendor workaround is to prevent users from executing Lua scripts or avoid replicas with replica-read-only disabled.

## MITRE ATT&CK

- T1595 Active Scanning
- T1608 Stage Capabilities
- T1190 Exploit Public-Facing Application
- T1110 Brute Force
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1203 Exploitation for Client Execution
- T1211 Exploitation for Stealth
- T1068 Exploitation for Privilege Escalation
- T1082 System Information Discovery
- T1210 Exploitation of Remote Services
- T1565 Data Manipulation

## Sources

- [Redis Security Advisory GHSA-8ghh-qpmp-7826 — Lua Use-After-Free may lead to remote code execution](https://github.com/redis/redis/security/advisories/GHSA-8ghh-qpmp-7826)
- [Redis 8.6.3 Release Notes](https://github.com/redis/redis/releases/tag/8.6.3)
- [NVD — CVE-2026-23631](https://nvd.nist.gov/vuln/detail/CVE-2026-23631)
- [Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server](https://cybersecuritynews.com/redis-rce-vulnerability-server/)
- [Wiz ZeroDay.Cloud 2025 — DarkReplica research disclosure](https://zeroday.cloud/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0713
