CVE-2026-21863Patch(lfprojects / valkey)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch lfprojects valkey systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • valkey

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-05); latest day: 1
  • 9 total mentions across 8 days

Affected systems

Vendors
Products
valkey

Deep dive

Activity timeline9 mentions / 8d
01122Mentions · 2026-02-23: 1Mentions · 2026-02-24: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-05: 2Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-05-18: 1PoC Mentioned / Linked · 2026-03-05: 1Patch / Workaround · 2026-03-05: 2Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-05-18: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-05: 2Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 102-2302-2402-2702-2803-0503-1203-1305-18
Signal classification3 categories
Patch
555.6%
Disclosure
333.3%
General
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-231
Disclosure1
2026-02-241
Disclosure1
2026-02-271
Disclosure1
2026-02-281
General1
2026-03-052
Patch2
2026-03-121
Patch1
2026-03-131
Patch1
2026-05-181
Patch1
Full discourse9 posts
  • cPanel@cPanel
    Patch

    EasyApache 4 v25.49 is now available: • Valkey 7.2 → 7.2.12 • Fix for CVE-2026-21863 (remote DoS via malformed cluster bus message) • Fix for CVE-2025-67733 (RESP protocol injection via Lua error_reply) Full change log → https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ #EasyApache #cPanelUpdates https://t.co/qsBFfRMGJR

    Post summary

    EasyApache 4 v25.49 includes patches for CVE-2026-21863 and CVE-2025-67733, with brief technical details but no proof of exploitation or payoff.

    11020541
    28.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Redis has two critical CVEs (CVE-2025-67733 & CVE-2026-21863) on Debian. Here is your practical guide: check your version, apply the fix, or mitigate with ACLs and iptables. Read more -> http://tinyurl.com/3kzpbaj7 #Debiar #Security https://t.co/mjmharjgTL

    Post summary

    The tweet alerts Debian users to two critical Redis CVEs and offers a practical guide to verify versions and apply vendor fixes or interim mitigations such as ACLs and iptables.

    100001.3K
    1.5K followersView on X
  • cPanel@cPanel
    Patch

    EasyApache 4 v25.49 is now available: • Valkey 7.2 → 7.2.12 • Fix for CVE-2026-21863 (remote DoS via malformed cluster bus message) • Fix for CVE-2025-67733 (RESP protocol injection via Lua error_reply) Full change log → https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ #EasyApache #cPanelUpdates https://t.co/KvZANzBtvz

    Post summary

    The tweet announces a new EasyApache update that patches CVE-2026-21863 and CVE-2025-67733, providing technical details of each vulnerability.

    00010343
    28.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-21863 Valkey Clusterbus Packet Processing Vulnerability Leading to Out-of-Bounds Read https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21863

    Post summary

    A new CVE-2026-21863 vulnerability in Valkey Clusterbus has been disclosed, identified as an out-of-bounds read.

    0001049
    4.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    The new Valkey 8.0.7 update for #Fedora 42 fixes two really nasty security holes. One (CVE-2026-21863) lets an attacker crash your entire cluster just by sending a bad packet to the cluster bus. Read more: 👉 https://tinyurl.com/3rzy9uu8 #Security https://t.co/R7rpV6I83p

    Post summary

    The tweet announces that the Valkey 8.0.7 update for Fedora 42 patches CVE‑2026‑21863, a denial‑of‑service flaw that can crash a cluster via a malformed packet.

    0000063
    1.3K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Critical DoS flaws in Valkey affect Fedora 42-43. CVE-2026-21863 and CVE-2025-67733 (PoC public) fixed in recent updates. Fedora users should patch immediately. #infosec https://threatcluster.io/cluster/critical-dos-vulnerabilities-in-valkey-affect-fedora-42-and--1ab0805c

    Post summary

    The post announces critical DoS CVEs (CVE-2026-21863, CVE-2025-67733) affecting Valkey on Fedora 42-43, notes that a public PoC exists, and urges users to apply recent patches immediately.

    00000106
    91 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-21863 (CVSS:7.5, HIGH) is Analyzed. Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with ac..https://nvd.nist.gov/vuln/detail/CVE-2026-21863 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-21863 is a high‑severity vulnerability affecting specific Valkey database versions, but no PoC, exploit, patch, or active exploitation information is provided.

    0000021
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-21863 (CVSS:7.5, HIGH) is Analyzed. Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with ac..https://nvd.nist.gov/vuln/detail/CVE-2026-21863 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2026‑21863 as a high‑severity flaw in older Valkey database versions, providing CVSS and version details but no exploit, PoC, or patch information.

    0000020
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21863 Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an… https://www.cve.org/CVERecord?id=CVE-2026-21863

    Post summary

    CVE-2026-21863 affects Valkey versions prior to 9.0.2, 8.1.6, 8.0.7, and 7.2.12, allowing a malicious actor with access to the clusterbus port to send a potentially harmful command.

    00000109
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsvalkey---

Explore more