CVE-2026-21863 impacts Valkey, a distributed key-value database, prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12. An unauthenticated attacker can send a malformed packet to the clusterbus port, leading to an out-of-bounds read and potential system crash. This vulnerability has a CVSS score of 7.5 (HIGH) due to its network attack vector, low attack complexity, and high availability impact. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.2.12CPE matchmatch criteria | cpe:2.3:a:lfprojects:valkey:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.0.7CPE matchmatch criteria | cpe:2.3:a:lfprojects:valkey:*:*:*:*:*:*:*:* | ||
>= 8.1.0, < 8.1.6CPE matchmatch criteria | cpe:2.3:a:lfprojects:valkey:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.2CPE matchmatch criteria | cpe:2.3:a:lfprojects:valkey:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Valkey vulnerabilities
Mar 18, 2026USN-8106-1: Valkey vulnerabilities
Mar 18, 2026valkey: Valkey: Denial of Service via invalid clusterbus packet
Feb 23, 2026Malformed Valkey Cluster bus message can lead to Remote DoS
Feb 10, 2026