← All CVEs NewScan detects
high

CVE-2026-23479

Use-after-free in the unblock-client flow -> remote code execution

Severity
high
Affected product
Redis
Affected versions
Redis ≥ 6.2.0, < 6.2.22
Affected versions
Redis ≥ 7.0.0, < 7.2.14
Affected versions
Redis ≥ 7.4.0, < 7.4.9
Affected versions
Redis ≥ 8.2.0, < 8.2.6
Affected versions
Redis ≥ 8.4.0, < 8.4.3
Affected versions
Redis ≥ 8.6.0, < 8.6.3
Fixed in
Redis 6.2.22 / 7.2.14 / 7.4.9 / 8.2.6 / 8.4.3 / 8.6.3
Added to NewScan
2026-08-06
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Redis from its response and reports this CVE when the detected version falls inside the affected range below.

Ranges taken from the Redis security advisory (2026-08-05 review), not inferred. Redis backports per maintained branch, so each CVE is ONE ROW PER BRANCH the advisory names a fixed version for - a branch the advisory does not list gets no row rather than a guessed range, so an older patched line is never falsely flagged.

COMPONENT VERSION RANGE

NewScan fingerprints Redis from its response and reports this CVE when the detected version falls inside the affected range below.

Ranges taken from the Redis security advisory (2026-08-05 review), not inferred. Redis backports per maintained branch, so each CVE is ONE ROW PER BRANCH the advisory names a fixed version for - a branch the advisory does not list gets no row rather than a guessed range, so an older patched line is never falsely flagged.

COMPONENT VERSION RANGE

NewScan fingerprints Redis from its response and reports this CVE when the detected version falls inside the affected range below.

Ranges taken from the Redis security advisory (2026-08-05 review), not inferred. Redis backports per maintained branch, so each CVE is ONE ROW PER BRANCH the advisory names a fixed version for - a branch the advisory does not list gets no row rather than a guessed range, so an older patched line is never falsely flagged.

COMPONENT VERSION RANGE

NewScan fingerprints Redis from its response and reports this CVE when the detected version falls inside the affected range below.

Ranges taken from the Redis security advisory (2026-08-05 review), not inferred. Redis backports per maintained branch, so each CVE is ONE ROW PER BRANCH the advisory names a fixed version for - a branch the advisory does not list gets no row rather than a guessed range, so an older patched line is never falsely flagged.

COMPONENT VERSION RANGE

NewScan fingerprints Redis from its response and reports this CVE when the detected version falls inside the affected range below.

Ranges taken from the Redis security advisory (2026-08-05 review), not inferred. Redis backports per maintained branch, so each CVE is ONE ROW PER BRANCH the advisory names a fixed version for - a branch the advisory does not list gets no row rather than a guessed range, so an older patched line is never falsely flagged.

COMPONENT VERSION RANGE

NewScan fingerprints Redis from its response and reports this CVE when the detected version falls inside the affected range below.

Ranges taken from the Redis security advisory (2026-08-05 review), not inferred. Redis backports per maintained branch, so each CVE is ONE ROW PER BRANCH the advisory names a fixed version for - a branch the advisory does not list gets no row rather than a guessed range, so an older patched line is never falsely flagged.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →