CVE Feed

    Dashboard / CVE / CVE-2026-27623

    CVE-2026-27623

    Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can cause the system to abort by triggering an assertion. When processing incoming requests, the Valkey system does not properly reset the networking state after processing an empty request. A malicious actor can then send a request that the server incorrectly identifies as breaking server side invariants, which results in the server shutting down. Version 9.0.3 fixes the issue. As an additional mitigation, properly isolate Valkey deployments so that only trusted users have access.

    Published:Feb 23, 2026
    Last Modified:Apr 17, 2026
    EPS:Feb 23, 2026
    EPSS Score:0.00148
    CVSS Score:7.5

    Affected Products

    Vendor
    Lfprojects
    Product
    Valkey
    Vendor
    Valkey-io
    Product
    Valkey

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High