CVE-2026-81934: Redis Vulnerability in TLS Data Processing

This text was generated using artificial intelligence (AI).On August 27, 2026, CVE-2026-81934 released for Redis. The vulnerability affects the function tlsProcessPendingData, which processes the list of outstanding TLS data if Redis is configured with TLS support. After a fix from the CNA on August 31, 2026, the CVSS score is 7.5 (v4.0) or 7.1 (v3.1), severity high; originally, the vulnerability was rated 9.8 (critical).

According to the corrected CVSS vector, an attack requires access from the adjacent network, low privileges, and high attack complexity. If successful, arbitrary commands can be executed with the privileges of the Redis server. According to the release notes, the error occurs when a command closes another pending connection. Therefore, Redis instances with TLS configuration are particularly relevant for prioritization.

Are my systems affected? Check now →