Try our Chrome extension
Easily add the current web-page from your browser directly into your changedetection.io tool, more great features coming soon!Changedetection.io needs your support!
You can help us by supporting changedetection.io on these platforms;
- Rate us at AlternativeTo.net
- Star us on GitHub
- Follow us at Twitter/X
- G2 Software reviews
- Check us out on LinkedIn
- And tell your friends and colleagues :)
The more popular changedetection.io is, the more time we can dedicate to adding amazing features!
Many thanks :)
changedetection.io team
Not yet seconds ago
False
Not yet seconds ago
Triggered text Ignored text Blocked text
4 days ago
tag:github.com,2008:https://github.com/redis/redis/releases Release notes from redis 2026-09-28T07:34:42Z tag:github.com,2008:Repository/156018/8.12-m02-int 2026-09-28T07:34:42Z 8.12-m02-int: Explain a test [TIMEOUT] instead of killing it silently (#15879) <p>A hung test run tells us almost nothing today. When no client has made<br> progress for --timeout seconds, test_server_cron prints the clients'<br> last reported state, SIGKILLs every server via force_kill_all_servers<br> and exits; --dump-logs only fires for a failed or excepted test, never<br> for a timeout. So a 20-minute hang costs a whole CI run and produces a<br> few lines.</p> <p>Collect the evidence before tearing the run down:</p> <p>Crash-report the surviving servers. SIGSEGV makes redis log a stack<br> trace of every one of its threads plus INFO, the client list and the<br> config (printCrashReport) and then die. The handler runs on whichever<br> thread takes the signal, so it works on a server whose event loop is<br> wedged -- exactly the case we cannot diagnose from outside. kill_server<br> already resorts to SIGSEGV for the same reason when a server won't exit,<br> but the timeout path never reaches it. Then print each server's crash<br> report, starting 10 lines above "REDIS BUG REPORT START" for context (or<br> the log's tail if there is no report, since that is then the only<br> evidence). Servers are children of the stuck client, which isn't reaping<br> them, so a dead one is a zombie that kill -0 still reports alive; wait<br> on is_running (via ps) instead.</p> <p>Report where in the test each client stopped, not just its last state.<br> Crash-reporting the servers usually unblocks a client by itself -- its<br> connection dies, the error unwinds, and the client's existing top-level<br> handler reports $::errorInfo, a Tcl stack trace naming the exact line --<br> so collect that first. A client stuck on something else is poked with<br> SIGUSR1, which it turns into a Tcl error with Tclx's "signal error":<br> that interrupts a blocking read, a long "after" and a polling loop<br> alike. Tclx is optional; without it a timeout simply reports no client<br> stack trace.</p> <p>Order matters here: the servers must be collected first, because<br> unblocking a client makes start_server kill the very servers we wanted a<br> report from.</p> <p>Also: read_from_test_client threw "expected non-negative integer" once a<br> reporting client exited, because we now pump the event loop while it<br> does.</p> <hr> <div class="markdown-alert markdown-alert-note"><p class="markdown-alert-title"><svg data-component="Octicon" class="octicon octicon-info mr-2" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z"></path></svg>Note</p><p><strong>Low Risk</strong><br> Changes are limited to the Tcl test harness timeout path; no<br> production server or runtime behavior is affected.</p> <p><strong>Overview</strong><br> When the suite hits <strong><code>--timeout</code></strong> (no client progress), it no longer<br> tears down immediately after printing each client’s last task. The test<br> server <strong>collects diagnostics first</strong>, then kills clients and servers as<br> before.</p> <p><strong>Server evidence:</strong> Still-running Redis instances from<br> <code>::active_servers</code> get <strong>SIGCONT</strong> (if stopped) and <strong>SIGSEGV</strong> so they<br> write a full crash report even when the event loop is wedged. Logs are<br> located under <code>tests/tmp</code> by pid, then <strong><code>dump_crash_report</code></strong> prints<br> the tail around <code>REDIS BUG REPORT START</code> (or the last 256KB if there is<br> no report). <strong><code>is_running</code></strong> treats zombies as dead so waits don’t hang<br> on unreaped children.</p> <p><strong>Client evidence:</strong> Clients send their OS pid on <code>ready</code> and<br> optionally advertise <strong><code>sigusr1-trace</code></strong> when Tclx is available. After<br> server dumps, the server waits briefly for natural <strong><code>exception</code></strong>/<code>err</code><br> unwinds, then sends <strong>SIGUSR1</strong> to remaining clients so Tclx turns it<br> into a stack trace. <strong><code>::in_timeout_report</code></strong> suppresses re-entrant<br> timeout cron, avoids fatal handling of those packets, and fixes<br> <strong><code>read_from_test_client</code></strong> when a client disconnects mid-report<br> (invalid length no longer spins or crashes the handler).</p> <p><strong>Order:</strong> Server crash collection runs <strong>before</strong> client stack traces<br> so unblocking a client doesn’t tear down servers before their reports<br> are captured.</p> <p><sup>Reviewed by <a href="https://cursor.com/bugbot" rel="nofollow">Cursor Bugbot</a> for commit<br> <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/redis/redis/commit/5927e7e9149ac45b2adea623ca4c4f0f4d570df6/hovercard" href="https://github.com/redis/redis/commit/5927e7e9149ac45b2adea623ca4c4f0f4d570df6"><tt>5927e7e</tt></a>. Bugbot is set up for automated<br> code reviews on this repo. Configure<br> <a href="https://www.cursor.com/dashboard/bugbot" rel="nofollow">here</a>.</sup></p> </div> <hr> <p>Co-authored-by: Claude Opus 5.5 (1M context) <a href="mailto:noreply@anthropic.com">noreply@anthropic.com</a></p> oranagra tag:github.com,2008:Repository/156018/8.10.2 2026-09-17T15:08:27Z 8.10.2 <p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5180522741" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15673" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15673/hovercard" href="https://github.com/redis/redis/pull/15673">#15673</a> Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li> <li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li> <li>RedisSearch: KNN queries on indexes with very long vector field names could cause the server to crash</li> <li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li> </ul> sundb tag:github.com,2008:Repository/156018/8.8.3 2026-09-17T15:04:35Z 8.8.3 <p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5180522741" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15673" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15673/hovercard" href="https://github.com/redis/redis/pull/15673">#15673</a> Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li> <li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li> <li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li> </ul> sundb tag:github.com,2008:Repository/156018/8.6.7 2026-09-17T15:01:42Z 8.6.7 <p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5180522741" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15673" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15673/hovercard" href="https://github.com/redis/redis/pull/15673">#15673</a> Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li> <li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li> <li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li> </ul> sundb tag:github.com,2008:Repository/156018/8.4.7 2026-09-17T14:58:05Z 8.4.7 <p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5180522741" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15673" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15673/hovercard" href="https://github.com/redis/redis/pull/15673">#15673</a> Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li> <li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li> <li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li> </ul> sundb tag:github.com,2008:Repository/156018/8.2.10 2026-09-17T14:53:52Z 8.2.10 <p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li> <li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li> <li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li> </ul> sundb tag:github.com,2008:Repository/156018/8.12-m01-int 2026-09-15T07:51:32Z 8.12-m01-int: Add aof_cmd_duration estimate for AOF reload RTO visibility <p>Expose a best-effort AOF replay-time estimate in INFO persistence so<br> operators can gauge reload RTO. Count time only for writes that enter<br> the AOF, credit leftover call() time to synthetic rewrites, and skip<br> the bookkeeping when AOF is off.</p> yinon-bit tag:github.com,2008:Repository/156018/8.10.1 2026-08-17T16:46:02Z 8.10.1 <p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li>(CVE-2026-62356) Miscalculated buffer size in <code>CMSketch</code> RDB loading may lead to heap OOB write</li> <li>Out-of-bounds access in TopK heap cleanup path (MOD-15410)</li> <li>Use-after-free in the TLS pending-data list when a command closes another pending connection</li> <li>A malicious RDB payload with an out-of-range <code>SLOT_INFO</code> slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution</li> <li>Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access</li> <li>Vector Sets: use-after-free when <code>VREM</code> mutates the HNSW graph while background <code>VSIM</code> threads are still running</li> <li>Vector Sets: a negative <code>hnsw_search()</code> return was treated as a huge unsigned count, reading past the end of the result arrays</li> <li>TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5070817913" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15594" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15594/hovercard" href="https://github.com/redis/redis/pull/15594">#15594</a> Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key</li> </ul> YaacovHazan tag:github.com,2008:Repository/156018/8.8.2 2026-08-17T16:41:01Z 8.8.2 <p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li>(CVE-2026-62356) Miscalculated buffer size in <code>CMSketch</code> RDB loading may lead to heap OOB write</li> <li>Out-of-bounds access in TopK heap cleanup path (MOD-15410)</li> <li>Use-after-free in the TLS pending-data list when a command closes another pending connection</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4910514260" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15478" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15478/hovercard" href="https://github.com/redis/redis/pull/15478">#15478</a> ACL key permission bypass in <code>SORT</code>, <code>GEORADIUS</code>/<code>GEORADIUSBYMEMBER</code> and <code>XREAD</code>/<code>XREADGROUP</code>: the keys validated by ACL could differ from the keys the command actually accesses</li> <li>A malicious RDB payload with an out-of-range <code>SLOT_INFO</code> slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution</li> <li>Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access</li> <li>Vector Sets: use-after-free when <code>VREM</code> mutates the HNSW graph while background <code>VSIM</code> threads are still running</li> <li>Vector Sets: a negative <code>hnsw_search()</code> return was treated as a huge unsigned count, reading past the end of the result arrays</li> <li>TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5070817913" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15594" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15594/hovercard" href="https://github.com/redis/redis/pull/15594">#15594</a> Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key</li> </ul> YaacovHazan tag:github.com,2008:Repository/156018/8.6.6 2026-08-17T16:39:37Z 8.6.6 <p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p> <h3>Security fixes</h3> <ul> <li>(CVE-2026-62356) Miscalculated buffer size in <code>CMSketch</code> RDB loading may lead to heap OOB write</li> <li>Out-of-bounds access in TopK heap cleanup path (MOD-15410)</li> <li>Use-after-free in the TLS pending-data list when a command closes another pending connection</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4910514260" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15478" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15478/hovercard" href="https://github.com/redis/redis/pull/15478">#15478</a> ACL key permission bypass in <code>SORT</code>, <code>GEORADIUS</code>/<code>GEORADIUSBYMEMBER</code> and <code>XREAD</code>/<code>XREADGROUP</code>: the keys validated by ACL could differ from the keys the command actually accesses</li> <li>A malicious RDB payload with an out-of-range <code>SLOT_INFO</code> slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution</li> <li>Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access</li> <li>Vector Sets: use-after-free when <code>VREM</code> mutates the HNSW graph while background <code>VSIM</code> threads are still running</li> <li>Vector Sets: a negative <code>hnsw_search()</code> return was treated as a huge unsigned count, reading past the end of the result arrays</li> <li>TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user</li> <li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5070817913" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15594" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15594/hovercard" href="https://github.com/redis/redis/pull/15594">#15594</a> Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key</li> </ul> YaacovHazan
For now, Differences are performed on text, not graphically, only the latest screenshot is available.
Screenshot requires a Content Fetcher ( Sockpuppetbrowser, selenium, etc ) that supports screenshots.