Critical Redis Vulnerability Could Let Attackers Execute Code and Hijack Servers
ID: e7cdf0dd-4737-5d0e-a58b-7699e235976b
STIX ID: report--e7cdf0dd-4737-5d0e-a58b-7699e235976b
Feed Name: GBHackers
This report describes “DarkReplica” (CVE-2026-23631), a critical authenticated remote code execution vulnerability in Redis’s replication and Lua functions engine that leverages a use-after-free during FULLRESYNC to corrupt lua_State and achieve arbitrary code execution; it details exploitation techniques (heap grooming, lua primitives, overwriting frealloc to call system()), affected versions, and fixed releases, and urges immediate patching, stricter replication controls, and reduced Lua functionality to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
