CVE-2026-66373

EUVD-2026-48762
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
mitreCNA
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 56.97%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
redisredis
𝑥
< 8.8.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
redis
bookworm
vulnerable
bookworm (security)
5:7.0.15-1~deb12u9
fixed
forky
vulnerable
sid
vulnerable
trixie
vulnerable
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
redis
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
redis
suse enterprise sap 15 SP5
6.2.6-150400.3.49.1
fixed
suse enterprise sap 15 SP6
7.2.4-150600.3.27.1
fixed
suse enterprise server 15 SP5
6.2.6-150400.3.49.1
fixed
suse enterprise server 15 SP6
7.2.4-150600.3.27.1
fixed
redis7
suse enterprise sap 15 SP5
7.0.8-150500.3.34.1
fixed
suse enterprise sap 15 SP6
7.0.8-150600.8.28.1
fixed
suse enterprise server 15 SP5
7.0.8-150500.3.34.1
fixed
suse enterprise server 15 SP6
7.0.8-150600.8.28.1
fixed