CVE-2026-27623 describes a denial-of-service vulnerability in Valkey, a distributed key-value database, affecting versions 9.0.0 through 9.0.2. A remote unauthenticated attacker can trigger an assertion failure, causing the Valkey server to shut down, by sending a specially crafted sequence of requests that exploit improper network state resetting. This vulnerability has a CVSS score of 7.5 (High), indicating a high impact on availability with low attack complexity and no user interaction required. There is currently no public exploit code available, nor is it known to be actively exploited, with minimal community discussion and no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0.0, < 9.0.3CPE matchmatch criteria | cpe:2.3:a:lfprojects:valkey:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.