AI description
CVE-2026-66373 describes a remote code execution vulnerability affecting Redis versions prior to 8.8.0. This flaw arises in specific circumstances where an authenticated attacker is able to execute the `RESTORE` command. The vulnerability is triggered by a double free condition. This occurs when a `RESTORE` payload references the same NACK (pending entry) through multiple consumers. Subsequently, deleting both consumers via `XGROUP DELCONSUMER` leads to the double free. This issue is noted as an incomplete fix for a previous vulnerability, CVE-2026-25243.
- Description
- Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
- Source
- cve@mitre.org
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 5.9
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- cve@mitre.org
- CWE-415
- Hype score
- Not currently trending
🚨 CVE-2026-66373: Redis RESTORE Buffer Overflow Critical Vulnerability Alert! redis is affected by CVE-2026-66373. 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-66373" Search Dork: service="redis" Exposure: 3.1m instances identified globally. ZoomEye Search
@zapstiko
1 Aug 2026
289 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
🚨 CVE-2026-66373: Redis RESTORE Buffer Overflow Critical Vulnerability Alert! redis is affected by CVE-2026-66373. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/JvFVkEDunl 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-66373" Search
@zoomeye_team
31 Jul 2026
1764 Impressions
10 Retweets
32 Likes
12 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-66373 Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (p… https://t.co/gR0mhmdYSM ----- Traducción: CVE-2026-66373 Red… https://t.co/utmtNg
@infoflowcloud
25 Jul 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes