Out-of-bounds read in Valkey - CVE-2026-21863
Published: April 27, 2026
Valkey
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the clusterbus packet processing code when processing a malformed clusterbus ping extension packet. A remote attacker can send a specially crafted clusterbus packet to cause a denial of service.
Exploitation requires access to the Valkey clusterbus port.