Double Free Affecting redis/redis package, versions [,6.2.23)[7.2.0,7.2.15)[7.4.0,7.4.10)[8.0.0,8.2.8)[8.4.0,8.4.5)[8.6.0,8.6.5)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.5% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Double Free vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-REDISREDIS-18306708
  • published25 Jul 2026
  • disclosed25 Jul 2026
  • creditUnknown

Introduced: 25 Jul 2026

NewCVE-2026-66373  (opens in a new tab)
CWE-415  (opens in a new tab)

How to fix?

Upgrade redis/redis to version 6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5 or higher.

Overview

Affected versions of this package are vulnerable to Double Free in the RESTORE process when the same NACK (pending entry) is referenced by more than one consumer. An attacker can achieve remote code execution by crafting a malicious RESTORE payload and deleting both consumers via the XGROUP DELCONSUMER command. This is only exploitable if an authenticated attacker can execute the RESTORE command and manipulate consumer groups in this specific manner.

CVSS Base Scores

version 4.0
version 3.1