CVE-2026-85522
valkey-io valkey Slot Migration cluster_migrateslots.c createSlotImportJob out-of-bounds
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.c of the component Slot Migration. The manipulation of the argument job_name results in out-of-bounds read. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 9.0.5 and 9.1.1 addresses this issue. The patch is identified as f4dc3ca09eb650c2fe14060090a41c524eca803f. Upgrading the affected component is advised.
| CWE | CWE-125 CWE-119 |
| Vendor | valkey-io |
| Product | valkey |
| Published | Sep 4, 2026 |
| Last Updated | Sep 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for valkey-io valkey
Be the first to know when new medium vulnerabilities affecting valkey-io valkey are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
valkey-io / valkey
9.0 9.1.0 9.5.0 9.5.1 9.5.2 9.5.3 9.5.4
References
vuldb.com: https://vuldb.com/vuln/398707 vuldb.com: https://vuldb.com/vuln/398707/cti vuldb.com: https://vuldb.com/cve/CVE-2026-85522 vuldb.com: https://vuldb.com/submit/895119 github.com: https://github.com/valkey-io/valkey/issues/4207 github.com: https://github.com/valkey-io/valkey/pull/4210 github.com: https://github.com/valkey-io/valkey/commit/f4dc3ca09eb650c2fe14060090a41c524eca803f github.com: https://github.com/valkey-io/valkey/releases/tag/9.1.1 github.com: https://github.com/valkey-io/valkey/
Credits
๐ VULL (VulDB User)