tag:github.com,2008:https://github.com/redis/redis/releases

Release notes from redis

2026-09-17T15:06:00Z tag:github.com,2008:Repository/156018/8.10.2 2026-09-17T15:08:27Z

8.10.2

<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5180522741" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15673" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15673/hovercard" href="https://github.com/redis/redis/pull/15673">#15673</a> Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li> <li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li> <li>RedisSearch: KNN queries on indexes with very long vector field names could cause the server to crash</li> <li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li> </ul> sundb tag:github.com,2008:Repository/156018/8.8.3 2026-09-17T15:04:35Z

8.8.3

<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5180522741" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15673" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15673/hovercard" href="https://github.com/redis/redis/pull/15673">#15673</a> Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li> <li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li> <li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li> </ul> sundb tag:github.com,2008:Repository/156018/8.6.7 2026-09-17T15:01:42Z

8.6.7

<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5180522741" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15673" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15673/hovercard" href="https://github.com/redis/redis/pull/15673">#15673</a> Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li> <li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li> <li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li> </ul> sundb tag:github.com,2008:Repository/156018/8.4.7 2026-09-17T14:58:05Z

8.4.7

<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5180522741" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15673" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15673/hovercard" href="https://github.com/redis/redis/pull/15673">#15673</a> Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li> <li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li> <li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li> </ul> sundb tag:github.com,2008:Repository/156018/8.2.10 2026-09-17T14:53:52Z

8.2.10

<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li> <li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li> <li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li> </ul> sundb tag:github.com,2008:Repository/156018/8.12-m01-int 2026-09-15T07:51:32Z

8.12-m01-int: Add aof_cmd_duration estimate for AOF reload RTO visibility

<p>Expose a best-effort AOF replay-time estimate in INFO persistence so<br> operators can gauge reload RTO. Count time only for writes that enter<br> the AOF, credit leftover call() time to synthetic rewrites, and skip<br> the bookkeeping when AOF is off.</p> yinon-bit tag:github.com,2008:Repository/156018/8.10.1 2026-08-17T16:46:02Z

8.10.1

<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li>(CVE-2026-62356) Miscalculated buffer size in <code>CMSketch</code> RDB loading may lead to heap OOB write</li> <li>Out-of-bounds access in TopK heap cleanup path (MOD-15410)</li> <li>Use-after-free in the TLS pending-data list when a command closes another pending connection</li> <li>A malicious RDB payload with an out-of-range <code>SLOT_INFO</code> slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution</li> <li>Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access</li> <li>Vector Sets: use-after-free when <code>VREM</code> mutates the HNSW graph while background <code>VSIM</code> threads are still running</li> <li>Vector Sets: a negative <code>hnsw_search()</code> return was treated as a huge unsigned count, reading past the end of the result arrays</li> <li>TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5070817913" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15594" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15594/hovercard" href="https://github.com/redis/redis/pull/15594">#15594</a> Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key</li> </ul> YaacovHazan tag:github.com,2008:Repository/156018/8.8.2 2026-08-17T16:41:01Z

8.8.2

<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li>(CVE-2026-62356) Miscalculated buffer size in <code>CMSketch</code> RDB loading may lead to heap OOB write</li> <li>Out-of-bounds access in TopK heap cleanup path (MOD-15410)</li> <li>Use-after-free in the TLS pending-data list when a command closes another pending connection</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4910514260" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15478" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15478/hovercard" href="https://github.com/redis/redis/pull/15478">#15478</a> ACL key permission bypass in <code>SORT</code>, <code>GEORADIUS</code>/<code>GEORADIUSBYMEMBER</code> and <code>XREAD</code>/<code>XREADGROUP</code>: the keys validated by ACL could differ from the keys the command actually accesses</li> <li>A malicious RDB payload with an out-of-range <code>SLOT_INFO</code> slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution</li> <li>Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access</li> <li>Vector Sets: use-after-free when <code>VREM</code> mutates the HNSW graph while background <code>VSIM</code> threads are still running</li> <li>Vector Sets: a negative <code>hnsw_search()</code> return was treated as a huge unsigned count, reading past the end of the result arrays</li> <li>TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5070817913" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15594" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15594/hovercard" href="https://github.com/redis/redis/pull/15594">#15594</a> Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key</li> </ul> YaacovHazan tag:github.com,2008:Repository/156018/8.6.6 2026-08-17T16:39:37Z

8.6.6

<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li>(CVE-2026-62356) Miscalculated buffer size in <code>CMSketch</code> RDB loading may lead to heap OOB write</li> <li>Out-of-bounds access in TopK heap cleanup path (MOD-15410)</li> <li>Use-after-free in the TLS pending-data list when a command closes another pending connection</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4910514260" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15478" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15478/hovercard" href="https://github.com/redis/redis/pull/15478">#15478</a> ACL key permission bypass in <code>SORT</code>, <code>GEORADIUS</code>/<code>GEORADIUSBYMEMBER</code> and <code>XREAD</code>/<code>XREADGROUP</code>: the keys validated by ACL could differ from the keys the command actually accesses</li> <li>A malicious RDB payload with an out-of-range <code>SLOT_INFO</code> slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution</li> <li>Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access</li> <li>Vector Sets: use-after-free when <code>VREM</code> mutates the HNSW graph while background <code>VSIM</code> threads are still running</li> <li>Vector Sets: a negative <code>hnsw_search()</code> return was treated as a huge unsigned count, reading past the end of the result arrays</li> <li>TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5070817913" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15594" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15594/hovercard" href="https://github.com/redis/redis/pull/15594">#15594</a> Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key</li> </ul> YaacovHazan tag:github.com,2008:Repository/156018/8.4.6 2026-08-17T16:38:05Z

8.4.6

<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li>(CVE-2026-62356) Miscalculated buffer size in <code>CMSketch</code> RDB loading may lead to heap OOB write</li> <li>Out-of-bounds access in TopK heap cleanup path (MOD-15410)</li> <li>Use-after-free in the TLS pending-data list when a command closes another pending connection</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4910514260" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15478" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15478/hovercard" href="https://github.com/redis/redis/pull/15478">#15478</a> ACL key permission bypass in <code>SORT</code>, <code>GEORADIUS</code>/<code>GEORADIUSBYMEMBER</code> and <code>XREAD</code>/<code>XREADGROUP</code>: the keys validated by ACL could differ from the keys the command actually accesses</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4023309612" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/14847" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/14847/hovercard" href="https://github.com/redis/redis/pull/14847">#14847</a> Out-of-bounds <code>argv</code> access during key extraction when checking ACL permissions of a KEYNUM keyspec command (e.g. <code>EVAL</code>) with wrong arity</li> <li>A malicious RDB payload with an out-of-range <code>SLOT_INFO</code> slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution</li> <li>Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access</li> <li>Vector Sets: use-after-free when <code>VREM</code> mutates the HNSW graph while background <code>VSIM</code> threads are still running</li> <li>Vector Sets: a negative <code>hnsw_search()</code> return was treated as a huge unsigned count, reading past the end of the result arrays</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5070817913" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15594" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15594/hovercard" href="https://github.com/redis/redis/pull/15594">#15594</a> Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key</li> </ul> YaacovHazan