Input validation error in Valkey - CVE-2026-27623
Published: April 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the request processing logic when handling malformed RESP requests after an empty request. A remote attacker can send a specially crafted request to cause a denial of service.
The issue can trigger an assertion failure that causes the server to abort and shut down.
Affected software
Fedora
valkey
How to mitigate CVE-2026-27623
valkey - update to 9.0.3-1.fc44