• Sources: Redis 8.8.1 release, Redis 6.2.23 release, heise online, HN 49024938
  • Summary: Redis published seven security releases on 2026-07-23: 6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5, and 8.8.1. The notes describe two memory-corruption classes, both reachable through crafted RESTORE payloads and both marked as possibly leading to remote code execution: a stream RESTORE payload that makes two consumers share the same NACK, causing a use-after-free, and out-of-bounds writes in the bundled RedisBloom and TDigest modules. The release notes carry no CVE identifiers. Security researcher Chaofan Shou reported on X that Kimi K3 agents found 19 zero-days in Redis 8.8.0 in about 90 minutes and published proof-of-concept code, and heise reports Redis confirmed specific exploits from that repository. The counts, timings, and the degree of agent autonomy are self-reported and not independently reproduced.
  • Why it matters: Redis is deployed as a default cache and queue in most stacks, the fixes span every supported branch back to 6.2, and RESTORE is reachable by any client permitted to write keys.
  • Follow-up: Watch for CVE assignments, distribution and managed-service backports, and whether the remaining reported findings produce further releases.

send feedback on this story