Use-after-free in Redis - CVE-2026-23631
Published: May 5, 2026
Redis
Redis Labs
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use-after-free in the Lua scripting synchronization mechanism when exploiting master-replica synchronization. A remote user can trigger the flaw through crafted Lua script execution to execute arbitrary code.
Only replicas with replica-read-only disabled are vulnerable.