Skip to content

RS: add RED-186912 security entry - #3801

Open
kaitlynmichael wants to merge 1 commit into
mainfrom
rs-nexus-red-186912
Open

RS: add RED-186912 security entry#3801
kaitlynmichael wants to merge 1 commit into
mainfrom
rs-nexus-red-186912

Conversation

@kaitlynmichael

@kaitlynmichael kaitlynmichael commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

Note

Low Risk
Documentation-only edits to release notes; no product code or configuration changes.

Overview
Adds a Redis Open Source security fixes bullet for ticket RED-186912 in the August 2026 Redis Software release notes for 8.0.20-96 and 8.2.0-46.

The new entry (no CVE label in the text) states that RESTORE and RDB loading can allow an authenticated user to trigger a use-after-free in stream consumer groups via a crafted serialized payload, with possible remote code execution. It is inserted in the same position in each per-version collapsible block (Redis 8.6.x through 6.2.x), immediately after the RedisBloom RESTORE CVE bullets and before CVE-2026-23631.

Reviewed by Cursor Bugbot for commit 1153244. Bugbot is set up for automated code reviews on this repo. Configure here.

@kaitlynmichael
kaitlynmichael requested a review from a team August 12, 2026 16:46
@kaitlynmichael kaitlynmichael self-assigned this Aug 12, 2026
@kaitlynmichael kaitlynmichael added bug Something isn't working rs Redis Software release-notes labels Aug 12, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working release-notes rs Redis Software

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants