๐Ÿ” CVE Alert

CVE-2026-85522

MEDIUM 5.3

valkey-io valkey Slot Migration cluster_migrateslots.c createSlotImportJob out-of-bounds

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.c of the component Slot Migration. The manipulation of the argument job_name results in out-of-bounds read. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 9.0.5 and 9.1.1 addresses this issue. The patch is identified as f4dc3ca09eb650c2fe14060090a41c524eca803f. Upgrading the affected component is advised.

CWE CWE-125 CWE-119
Vendor valkey-io
Product valkey
Published Sep 4, 2026
Last Updated Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for valkey-io valkey

Be the first to know when new medium vulnerabilities affecting valkey-io valkey are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

valkey-io / valkey
9.0 9.1.0 9.5.0 9.5.1 9.5.2 9.5.3 9.5.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/398707 vuldb.com: https://vuldb.com/vuln/398707/cti vuldb.com: https://vuldb.com/cve/CVE-2026-85522 vuldb.com: https://vuldb.com/submit/895119 github.com: https://github.com/valkey-io/valkey/issues/4207 github.com: https://github.com/valkey-io/valkey/pull/4210 github.com: https://github.com/valkey-io/valkey/commit/f4dc3ca09eb650c2fe14060090a41c524eca803f github.com: https://github.com/valkey-io/valkey/releases/tag/9.1.1 github.com: https://github.com/valkey-io/valkey/

Credits

๐Ÿ” VULL (VulDB User)