CVE-2026-23631Disclosure(redis / redis)

HIGHCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch redis redis systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • redis

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 10 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 13 signals
  • Disclosure: 9 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 6 mentions (2026-06-08); latest day: 1
  • 19 total mentions across 10 days

Affected systems

Vendors
Products
redis

Deep dive

Activity timeline19 mentions / 10d
02356Mentions · 2026-05-05: 2Mentions · 2026-05-07: 2Mentions · 2026-06-02: 1Mentions · 2026-06-03: 1Mentions · 2026-06-04: 2Mentions · 2026-06-07: 2Mentions · 2026-06-08: 6Mentions · 2026-06-15: 1Mentions · 2026-07-23: 1Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-06-03: 1PoC Mentioned / Linked · 2026-06-04: 1PoC Mentioned / Linked · 2026-07-23: 1Exploit Tool / Code · 2026-06-03: 1Exploit Tool / Code · 2026-06-04: 1Exploit Tool / Code · 2026-07-23: 1Active Exploitation · 2026-06-08: 1Patch / Workaround · 2026-06-04: 1Patch / Workaround · 2026-06-07: 1Patch / Workaround · 2026-06-08: 3Patch / Workaround · 2026-07-23: 1Technical Details · 2026-05-05: 2Technical Details · 2026-06-02: 1Technical Details · 2026-06-04: 1Technical Details · 2026-06-07: 2Technical Details · 2026-06-08: 5Technical Details · 2026-06-15: 1Technical Details · 2026-07-23: 105-0505-0706-0206-0306-0406-0706-0806-1507-2308-27
Signal classification6 categories
Disclosure
947.4%
Patch
421.1%
General
210.5%
Exploit
210.5%
PoC
15.3%
Active Exploitation
15.3%
Referenced assets20 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure2
2026-05-072
Disclosure1General1
2026-06-021
Disclosure1
2026-06-031
Exploit1
2026-06-042
General1PoC1
2026-06-072
Disclosure1Patch1
2026-06-086
Active Exploitation1Disclosure2Patch3
2026-06-151
Disclosure1
2026-07-231
Exploit1
2026-08-271
Disclosure1
Full discourse19 posts
  • Yoni Sherez@yoyosh__
    Disclosure

    Happy to finally share my Redis research from http://zeroday.cloud 2025! DarkReplica (CVE-2026-23631) is a Use-After-Free in Redis's built-in Lua engine. Full technical writeup: https://www.zeroday.cloud/blog/redis-cve-2026-23631-dark-replica

    Post summary

    The article announces CVE-2026-23631, a Use-After-Free flaw in Redis's Lua engine, and provides a technical writeup for researchers.

    114059217.2K
    85 followersView on X
  • dbugs@ptdbugs
    Exploit

    Full-chain RCE exploit for RedisBloom (likely CVE-2026-25589) published. PT ID: PT-2026-37093 For informational purposes only. Type of vulnerability: Heap Buffer Overflow / Out-of-Bounds Read-Write → Authenticated RCE Affected component: RedisBloom, TDigest structure The vendor has reportedly published a full remote exploit for a vulnerability in RedisBloom. The attack is based on insufficient validation of serialized TDigest data when loaded via the RESTORE command. A specially crafted object causes an out-of-bounds write to the heap. The publication includes Python (exploit) and Bash (stand preparation) scripts. The reported vulnerability corresponds to CVE-2026-25589 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-37093). Redis disclosed the vulnerability -> (https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/) on May 5, 2026, stating that an authenticated user with permission to RESTORE could send a specially crafted payload, causing incorrect memory access and potentially achieving code execution within the Redis process. The vulnerability received a CVSS score of 7.7 according to Redis; NVD also lists a CVSS 3.1 score of 8.8. Patches were released in RedisBloom 2.8.20, 2.6.28, and 2.4.23, as well as in updated Redis OSS/CE branches. As a temporary measure, Redis recommends restricting the RESTORE privilege using ACLs. RedisBloom provides probabilistic data structures. The affected TDigest structure is used for approximate percentile and quantile calculations in data streams. Starting with Redis 8, probabilistic structures, including TDigest, are included in the standard Redis binary distributions. Redis -> (https://redis.io/tutorials/what-is-redis/) is a high-performance data store that primarily operates in memory. It is used as a NoSQL database, cache, session store, message broker, and task queue. Because it works with data in RAM, Redis provides low latency and is often used to accelerate high-traffic websites, APIs, and distributed applications. Redis Redis is widely used worldwide. According to the Stack Overflow Developer Survey 2025, 30.7% of professional developers worked with Redis in the past year, ranking fifth among the databases listed in the survey. #dbugs_darkweb

    Post summary

    A full-chain RCE exploit for RedisBloom CVE-2026-25589 has been published, including Python and Bash scripts, with detailed vulnerability technicals and available patches.

    280522310.1K
    3.4K followersView on X
  • Clandestine@akaclandestine
    Exploit

    GitHub - yoyosh/DarkReplica: CVE-2026-23631 (DarkReplica) Redis Exploit · GitHub https://github.com/yoyosh/DarkReplica

    Post summary

    The text references a GitHub repository that presumably hosts a functional exploit for CVE‑2026‑23631, but provides no evidence of active exploitation, patches, or detailed technical information.

    015044203.7K
    62.5K followersView on X
  • Xint@xint_official
    Disclosure

    CVE-2026-23479 in was one of the high severity bugs we found when we won at @wiz_io's ZeroDay Cloud competition. Be on the lookout soon for the technical deep dive on ZDC blog - this was a really interesting bug because of its subtlety. The complex interaction between portions of code far apart from each other in the codebase likely wouldn't have been noticed by humans or traditional SAST tools but can now be found in hours through AI with the right scaffolding Big thanks to the teams at @Redisinc and Wiz for the collaboration https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/

    Post summary

    The post announces the discovery of high‑severity CVE-2026-23479 during a ZeroDay Cloud competition, noting its subtle nature and forthcoming technical deep dive, but provides no PoC, exploit, active‑exploitation, patch, or detailed technical information.

    13032203.2K
    1.4K followersView on X
  • elhacker.NET@elhackernet
    Patch

    Grave vulnerabilidad RCE de Redis permite control total del servidor En mayo de 2026, los desarrolladores de Redis corrigieron una vulnerabilidad crítica de ejecución remota de código (RCE) tras la autenticación, denominada DarkReplica (CVE-2026-23631) https://blog.elhacker.net/2026/06/grave-vulnerabilidad-rce-de-redis.html

    Post summary

    Redis released a patch for a critical remote code execution (RCE) vulnerability, CVE-2026-23631, that could allow full server control after authentication.

    05036112.9K
    141.0K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    5 CVEs in Redis https://www.openwall.com/lists/oss-security/2026/06/03/18 CVE‑2026‑23479: Use-After-Free in unblock client flow may lead to Remote Code Execution CVE‑2026‑25243,CVE-2026-25588,CVE‑2026‑25589: Invalid Memory Access in RESTORE Command [...] May Lead to RCE CVE-2026-23631: Lua UAF may lead to RCE

    Post summary

    The text announces five Redis CVEs, detailing their vulnerability types and potential for remote code execution, but does not provide PoC, patches, or evidence of active exploitation.

    140841.5K
    4.7K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Discover the Redis DarkReplica vulnerability (CVE-2026-23631). Learn how this replication flaw allows code execution and how to patch your servers. #Redis #DarkReplica #Cybersecurity #InfoSec #DatabaseSecurity #BugBounty #TechNews https://meterpreter.org/redis-darkreplica-vulnerability/ https://t.co/opLDG3Ey0r

    Post summary

    The tweet announces Redis DarkReplica CVE-2026-23631, notes its RCE potential, and urges users to apply patches.

    00050365
    12.6K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Redis の脆弱性 CVE-2026-23631 が FIX:RCE とサーバを乗っ取りの可能性 https://iototsecnews.jp/2026/06/08/critical-redis-vulnerability-could-let-attackers-execute-code-and-hijack-servers/ 脆弱性 CVE-2026-23631 は、単純な入力検証の不備ではなく、Redis の内部機能における想定外の相互作用から生じる欠陥です。問題の中心となるのは、Lua 関数の実行中にもレプリケーション処理が進行できる設計です。本来は制限されるべき処理がありますが、レプリケーション・トラフィックは十分な状態確認なしに処理されるため、レース・コンディションが発生し、使用中の lua_State が解放される状況が生まれます。その結果、解放後メモリ使用が発生し、最終的には任意のコード実行へ発展します。ご利用のチームは、ご注意ください。 #CVE202623631 #OpenSource #Redis #Vulnerability

    Post summary

    Highlights a critical Redis flaw (CVE‑2026‑23631) that can lead to arbitrary code execution via a race condition, but provides no PoC, exploit code, or patch information.

    02001167
    499 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-23631 Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronizati… https://www.cve.org/CVERecord?id=CVE-2026-23631 ----- Traducción: CVE-2026-23631 Red… http://infoflow.cloud`

    Post summary

    The post announces a newly disclosed Redis vulnerability (CVE‑2026‑23631) that allows authenticated users to exploit master‑replica synchronization, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0101053
    75 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-8732 2 - CVE-2026-23631 3 - CVE-2026-25243 4 - CVE-2026-46333 5 - CVE-2026-23479 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet simply lists five trending CVE identifiers with a link to a dashboard, providing no further technical or exploitation information.

    00010136
    1.7K followersView on X
  • Kovar@richardkovar
    Disclosure

    @Umesh__digital https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/

    Post summary

    The tweet shares a link to a Redis security advisory covering multiple CVEs, providing no further details about exploitation, mitigation or technical specifics.

    00000178
    508 followersView on X
  • moton@moton
    Disclosure

    Redis DarkReplica Exploit: CVE-2026-23631 Public Disclosure - https://securityonline.info/redis-darkreplica-exploit-cve-2026-23631/

    Post summary

    The post announces the public disclosure of the Redis DarkReplica exploit CVE‑2026‑23631, with no detailed PoC, exploit code, or mitigation information provided.

    0000077
    659 followersView on X
  • UNDERCODE NEWS@UndercodeNews
    Disclosure

    🚨 DarkReplica #CVE-2026-23631: How a Silent #Redis Replication Flaw Can Collapse Servers Into Full Remote Takeover + Video -Fact Checker: ✅: 0 ❌: 2 || 0/2 → Score: 0% 🤏🏻 -Prediction: 📈 1 Positive | 📉 0 Negative http://undercodenews.com/darkreplica-cve-2026-23631-how-a-silent-redis-replication-flaw-can-collapse-servers-into-full-remote-takeover-video/

    Post summary

    The article announces CVE‑2026‑23631, describing a silent Redis replication flaw that could lead to full remote takeover, but does not provide a PoC, exploit, or patch information.

    0000039
    910 followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: Redis DarkReplica (CVE-2026-23631) - post-auth Lua use-after-free yields host RCE. 9 detections, 12 IOCs. https://intel.threadlinqs.com/threat/TL-2026-0713 #ThreatIntel #Redis #RCE https://t.co/KEw9SVOAKo

    Post summary

    Threat intelligence reports that Redis DarkReplica (CVE‑2026‑23631) is being actively exploited via a post-auth Lua use‑after‑free leading to host RCE, with nine detections and multiple IOCs.

    0000052
    58 followersView on X
  • ThreadLinqs@threadlinqs
    Patch

    NEW THREAT INTEL: Redis DarkReplica (CVE-2026-23631) - post-auth Lua use-after-free chains to host RCE. Fixed in 8.6.3. https://intel.threadlinqs.com/threat/TL-2026-0713 #ThreatIntel #Redis #RCE https://t.co/sRhNWkjzrZ

    Post summary

    Threat intel reports a post‑auth Lua use‑after‑free RCE in Redis DarkReplica (CVE‑2026‑23631) that has been fixed in version 8.6.3.

    0000053
    58 followersView on X
  • Israel@f1tym1
    Patch

    Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server https://ift.tt/DmfZ0L7 In May 2026, Redis developers fixed a dangerous post-authentication remote code execution vulnerability, dubbed DarkReplica (CVE-2026-23631), that allowed attacker…

    Post summary

    Redis disclosed CVE-2026-23631 (DarkReplica) as a post‑authentication RCE and released a patch in May 2026; no PoC or active exploitation details are provided.

    0000063
    993 followersView on X
  • dbugs@ptdbugs
    PoC

    Redis-server Lua use-after-free may allow remote code execution CVE: CVE-2026-23631 PT ID: PT-2026-37086 Vendor: Redis Product: Redis CVSS: 8.1 Credits: n/a Description: Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-23631 • https://github.com/redis/redis/security/advisories/GHSA-8ghh-qpmp-7826 • https://github.com/redis/redis/releases/tag/8.6.3 PoC/Exploit: https://github.com/yoyosh/DarkReplica #dbugs_vuln

    Post summary

    A use-after-free flaw in Redis's Lua scripting allows authenticated attackers to achieve remote code execution; a PoC exists (GitHub), the issue is patched in v8.6.3, and a workaround is advised.

    000001.2K
    1.3K followersView on X
  • Ashley@ashleykZA
    General

    4 High, and 1 Medium CVE in Redis https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/

    Post summary

    The post notes that Redis has disclosed four high‑severity and one medium‑severity CVEs and provides a link to the official security advisory.

    0000034
    1.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23631 Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronizati… https://www.cve.org/CVERecord?id=CVE-2026-23631

    Post summary

    The text presents a legitimate Redis vulnerability (CVE-2026‑23631) that permits an authenticated attacker to abuse master‑replica synchronization, but it does not provide proof of concept, exploit code, or remediation guidance.

    00000152
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredisredis---

Explore more