7.2.14
Valkey 7.2.14 - Released Tue 21 July 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security Fixes
- CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
- CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
- Strictly check CRLF when parsing requests and reject malformed input as a protocol error instead of misparsing it by @enjoy-binbin (#2872)
- Fix a memory leak in
ZDIFFandZDIFFSTOREwhen the result set becomes empty during computation by @sarthakaggarwal97 (#3342) - Fix a double free when loading a stream consumer group from a corrupted RDB or RESTORE payload by @enjoy-binbin (#3498)
- Fix a potential crash from a NULL pointer dereference when updating the TLS pending-data flag by @zuiderkwast (#3641)
- Fix a Lua VM crash when loading functions after
FUNCTION FLUSH ASYNCand ensure flushed scripts' memory is released by @enjoy-binbin (#1826) - Fix a use-after-free when a module unregisters and re-registers a cluster message receiver by @eifrah-aws (#3846)
- Fix a file descriptor leak when a blocking connection attempt times out, e.g. during
MIGRATEto an unreachable host by @madolson (#3541) - Fix a crash in the module API when
VM_GetLRU,VM_SetLRU,VM_GetLFU, orVM_SetLFUis called with a NULL key by @yaronsananes (#3610) - Fix invalid memory access when loading a malformed zipmap payload via
RESTORE(CVE-2026-25243) by @ranshid (#3619) - Reject zipmap payloads whose length fields overflow, which could cause out-of-bounds access on 32-bit platforms via
RESTOREby @madolson (#3920) - Reject NAN scores in listpack and ziplist encoded sorted sets on RDB/
RESTOREload, preventing a later server crash by @madolson (#3921) - Fix a startup crash when generating
INFOoutput on 32-bit systems wheretime_tis 64-bit, such as Alpine 3.23 by @chenshi5012 (#3787) - Fix use of uninitialized memory when registering Lua functions with
FUNCTION LOADby @enjoy-binbin (#2750) - Fix listpack corruption and server crash when
XTRIMmarks the last entry in a stream listpack node as deleted by @smkher (#3591) - Fix
COMMAND INFOreturning the subcommands field as a RESP3 Set instead of an Array for commands without subcommands by @rickrams (#3939) - Reject control characters in
SENTINEL SETvalues and escape them on config rewrite to prevent config-file injection by @eifrah-aws (#3847) - Reject control characters and unsafe delimiters in cluster AUX fields and
cluster-announce-ipto prevent nodes.conf injection by @eifrah-aws (#3848) - Fix
lua-enable-insecure-apihaving no effect when enabled at startup via the config file or command line by @enjoy-binbin (#3548) - Log the real error (e.g.
Connection reset by peer) instead of the misleadingSuccesson replication sync I/O errors by @abmathur-ie (#3580) - Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long paths by @pkhartsk (#3843)
- Fix
valkey-cli --cluster del-nodefailing withNo such node IDwhen removing unreachable or failed nodes by @yang-z-o (#3209) - Fix
valkey-cli --cluster fixassigning all uncovered slots to the same primary instead of spreading them randomly by @abmathur-ie (#3586)
Full Changelog: 7.2.13...7.2.14