Skip to content

[chart/redis-ha][BUG] RCE in v8.8.0 - CVE-2026-81934 #417

Description

@muellerst-hg

Describe the bug
Redis identified and remediated a use-after-free vulnerability in TLS pending-data processing. Under specific conditions, an authenticated attacker could trigger the flaw and potentially execute remote code.
https://redis.io/blog/security-advisory-cve-2026-81934/

The current values.yaml points to redis 8.8.0-alpine and should be updated to 8.8.2-alpine

Additional context
https://nvd.nist.gov/vuln/detail/cve-2026-81934 with CVSS 9.8

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

bugSomething isn't working

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions