Valkey 8.1.9 - Released Tue 21 July 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security Fixes
- CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
- CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
- Fix clients being left on the wrong database after module keyspace notifications from commands like
MOVEandCOPYby @enjoy-binbin (#4024) - Fix an I/O thread job queue memory-ordering race that could trigger an assertion crash on ARM/aarch64 by @jjuleslasarte (#3878)
- Reject zipmap
RESTOREpayloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920) - Reject NAN scores when loading listpack/ziplist-encoded sorted sets, preventing a crash from crafted
RESTOREpayloads by @madolson (#3921) - Fix a startup crash when generating
INFOoutput on 32-bit systems wheretime_tis 64-bit (e.g. Alpine time64) by @chenshi5012 (#3787) - Fix
COMMAND INFOin RESP3 to reply with an empty Array instead of a Set for commands without subcommands by @rickrams (#3939) - Reject invalid characters in cluster AUX fields and
cluster-announce-ipto preventnodes.confcorruption and injection by @eifrah-aws (#3848) - Fix
lua-enable-insecure-apihaving no effect when enabled at startup via config file or command line by @enjoy-binbin (#3548) - Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long installation paths by @pkhartsk (#3843)
Full Changelog: 8.1.8...8.1.9