CVE-2026-23479 Redis Use-After-Free RCE

Redis Use-After-Free Remote Code Execution Vulnerability (CVE-2026-23479)

Tim Reed

Technical Director

In May 2026, Redis disclosed a high severity memory safety vulnerability tracked as CVE-2026-23479. The issue affects the Redis server, a widely deployed in memory data structure store used for caching, messaging, and real time analytics across cloud and on premises environments. The vulnerability exists in the client unblocking logic and may allow an authenticated attacker to achieve remote code execution under specific conditions.

Redis RCE vulnerability details

CVE-2026-23479 is a use after free vulnerability in the Redis server unblock client flow. Redis supports blocking commands that suspend client execution until a key becomes available. When such a command is resumed, the server attempts to re process the original request. In the vulnerable code path, Redis fails to verify whether the client object remains valid after command re execution.

An authenticated attacker can deliberately trigger eviction of a blocked client while this re execution is in progress. This results in Redis accessing memory that has already been freed. With careful manipulation of heap state, this condition can be escalated into arbitrary memory writes, ultimately allowing execution of attacker controlled commands in the context of the Redis server process.

The flaw was introduced in Redis version 7.2.0 and remained present across multiple stable branches for over two years. Redis server versions 7.2.0 up to but not including 8.6.3 are affected by the flaw.

Impact of the Redis Use-After-Free RCE

From a technical perspective, successful exploitation may lead to full remote code execution on the host system. This includes the ability to execute operating system commands, modify application data, or disable Redis entirely. While the vulnerability requires an authenticated session, many Redis deployments remain exposed with unauthenticated access by default, which materially increases the likelihood of exploitation

The business impact can be significant. Redis is frequently used as a shared infrastructure component, meaning compromise may provide a foothold into wider application stacks. Organisations may face service disruption, data exposure, and regulatory consequences if personal or sensitive data is affected. In cloud environments, misconfigured Redis instances with weak authentication increase the practical risk of exploitation.

Remediation for CVE-2026-23479

Redis has addressed CVE-2026-23479 in version 8.6.3. Organisations running self managed Redis deployments should prioritise upgrading to this release or later. Redis Cloud customers have already received the fix as part of managed service updates.

Where immediate upgrading is not possible, organisations should restrict network access to Redis instances, enforce authentication, and limit client privileges. These measures reduce exposure but should not be treated as a substitute for patching.

How can Sentrium help?

Sentrium supports organisations in identifying and reducing exposure to vulnerabilities affecting core infrastructure services. Through penetration testing, configuration reviews, and ongoing security assessments, we help validate whether issues such as CVE-2026-23479 can be exploited in real world environments and provide clear, practical remediation guidance.

If you would like to discuss how this vulnerability may affect your environment, or need support assessing your exposure, you can get in touch with the Sentrium team.

Exploring cyber security

  1. Information required to scope a penetration test accurately

    July 28, 2026

    What information do you need to scope a penetration test?

    Read more arrow_right_alt

  2. Staging or production environment for penetration testing?
  3. How much does a penetration test cost?

    June 4, 2026

    How much does a penetration test cost?

    Read more arrow_right_alt

  4. Common vulnerabilities in AI-developed applications found in penetration testing

    May 21, 2026

    Common vulnerabilities in AI-developed applications

    Read more arrow_right_alt

  5. AI penetration testing

    May 15, 2026

    What is AI penetration testing?

    Read more arrow_right_alt

  6. What's the difference between penetration testing and vulnerability assessment?

Ready to discover your security gaps?

Get in touch