CVE-2026-86227 | valkey-io valkey up to 9.0.5/9.1.1 src/kvstore.c kvstoreGetHashtable didx out-of-bounds (Issue 4222)

SecurityVulns

A vulnerability, which was classified as problematic, has been found in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bounds read.

The identification of this vulnerability is CVE-2026-86227. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

To fix this issue, it is recommended to deploy a patch.

Exploitation requires cluster mode plus attacker-controlled dump.rdb at startup (data-dir write access, replication feed, or a stored crafted RDB) – an attacker-position DoS at boot, not network pre-auth. The issue report was closed stating it “is worth fixing for the sake of memory safety… but I don’t think it meets our bar for a security disclosure.”VulDB Recent EntriesRead More