logo

Critical Redis Vulnerability Could Let Attackers Execute Code and Hijack Servers

ID: e7cdf0dd-4737-5d0e-a58b-7699e235976b

STIX ID: report--e7cdf0dd-4737-5d0e-a58b-7699e235976b

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-06-08

Date Updated: 2026-07-21

Author: Divya

...
...

This report describes “DarkReplica” (CVE-2026-23631), a critical authenticated remote code execution vulnerability in Redis’s replication and Lua functions engine that leverages a use-after-free during FULLRESYNC to corrupt lua_State and achieve arbitrary code execution; it details exploitation techniques (heap grooming, lua primitives, overwriting frealloc to call system()), affected versions, and fixed releases, and urges immediate patching, stricter replication controls, and reduced Lua functionality to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.