Valkey

Databases & DataBSD-3-Clause

A high-performance key-value datastore.

Latest 9.0.6 · by Linux FoundationWritten in CWebsitevalkey-io/valkeyRSS

Branches

9.1
9.1.2
9.0
9.0.6
8.1
8.1.10
8.0
8.0.11
7.2
7.2.14

Release activity

Release activity — 14 releases across 6 days since May 6, 2026. Each cell is one day; darker means more releases that day. Nothing is recorded before May 6, 2026. Older weeks are hidden at this screen width.
JunJulAugSep
SundayNo releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026No releases on Aug 16, 2026No releases on Aug 23, 2026No releases on Aug 30, 2026No releases on Sep 6, 2026
MondayNo releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026No releases on Aug 10, 2026No releases on Aug 17, 2026No releases on Aug 24, 20262 releases on Aug 31, 2026No releases on Sep 7, 2026
TuesdayNo releases on May 26, 20261 release on Jun 2, 2026No releases on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 20265 releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026No releases on Aug 11, 2026No releases on Aug 18, 2026No releases on Aug 25, 20262 releases on Sep 1, 2026No releases on Sep 8, 2026
WednesdayNo releases on May 27, 2026No releases on Jun 3, 2026No releases on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026No releases on Aug 12, 2026No releases on Aug 19, 2026No releases on Aug 26, 2026No releases on Sep 2, 2026No releases on Sep 9, 2026
ThursdayNo releases on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026No releases on Aug 13, 2026No releases on Aug 20, 2026No releases on Aug 27, 2026No releases on Sep 3, 2026No releases on Sep 10, 2026
FridayNo releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026No releases on Aug 14, 2026No releases on Aug 21, 2026No releases on Aug 28, 2026No releases on Sep 4, 2026
SaturdayNo releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026No releases on Aug 15, 2026No releases on Aug 22, 2026No releases on Aug 29, 2026No releases on Sep 5, 2026

14 releases since May 6, 2026, busiest day 5

Changelog

What changed from 8 to 9
Filter releases by branch
14 of 14 releases

9.0.6

Latest
Fixed 18
  • Fix crashes, assertion failures, and hangs when using RDMA together with IO threads
  • Fix a double free when a module timer callback stops its own timer with ValkeyModule_StopTimer
  • Fix torn RESP3 push frames when a client publishes a large message to a channel it is also subscribed to
  • RESET now clears CLIENT IMPORT-SOURCE state so reused pooled connections regain normal key expiration semantics
  • Truncated AOF files now discard an incomplete MULTI block entirely, preventing loss of later writes after another restart
  • Fix an ACL bypass in GEORADIUS and GEORADIUSBYMEMBER where duplicate STORE options checked only the first destination key
Deprecated 1
  • sanitize-dump-payload is now a deprecated no-op
Security 1
  • Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL

From Valkey

Valkey 9.0.6 - Released Tue 01 September 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes
  • GHSA-jcj7-v34w-v9vv: Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL. Only affects servers built with USE_RDMA and configured with an RDMA listener (#4534)
Bug Fixes
  • Fix crashes, assertion failures, and hangs when using RDMA together with IO threads by @quanyeyang (#3335)
  • Fix a double free when a module timer callback stops its own timer with ValkeyModule_StopTimer by @quanyeyang (#4211)
  • Fix torn RESP3 push frames when a client publishes a large message to a channel it is also subscribed to by @quanyeyang (#4253)
  • RESET now clears CLIENT IMPORT-SOURCE state so reused pooled connections regain normal key expiration semantics by @tjade273 (#3973)
  • Truncated AOF files now discard an incomplete MULTI block entirely, preventing loss of later writes after another restart by @chzhoo (#4342)
  • Fix an ACL bypass in GEORADIUS and GEORADIUSBYMEMBER where duplicate STORE options checked only the first destination key by @tjade273 (#3971)
  • Fix a use-after-free crash when a cluster message arrives for a message type registered by an unloaded module by @enjoy-binbin (#4360)
  • Always deep-validate payloads on RDB load and RESTORE, preventing deferred assertion crashes; sanitize-dump-payload is now a deprecated no-op by @jjuleslasarte (#3721)
  • Fix out-of-bounds memory access when registering or receiving cluster module messages of type 255, which is now a valid type by @enjoy-binbin (#4410)
  • AOF loading no longer applies ACL checks, preventing silent data loss when replaying commands with a disabled default user by @lukepalmer (#3984)
  • Fix a client memory accounting leak that inflated the mem_clients_normal INFO field on replicas after primary disconnects by @enjoy-binbin (#4395)
  • Fix a permanent client hang when a blocking command such as BLPOP is pipelined with a partially received next command by @foobar (#4531)
  • HGETEX now requires write permission on the key, so read-only ACL users can no longer change field TTLs or delete fields by @ranshid (#4576)
  • Compare the full TLS certificate CN when authenticating, so an embedded NUL cannot impersonate a truncated ACL username by @madolson (#4577)
  • Restore read performance with IO threads on TCP/TLS by applying extra read-completion handling only to RDMA connections by @quanyeyang (#4414)
  • Restore write performance with IO threads on TCP/TLS by limiting post-write safety checks to RDMA connections by @quanyeyang (#4452)
  • Fix atomic slot migration protocol errors with IO threads by not offloading export connection writes while snapshotting by @satheeshaGowda (#4104)
  • Reject invalid slot import ranges when loading an RDB, preventing corrupted files from creating bad migration state by @enjoy-binbin (#4229)
  • Reject RDB slot-import records with an invalid job name length, fixing an out-of-bounds read during startup by @quanyeyang (#4210)
  • Fix a crash when COPY ends with a bare DB token during slot migration, and block cross-DB COPY regardless of option order by @madolson (#4301)
  • HPERSIST, HTTL, HPTTL, HEXPIRETIME, and HPEXPIRETIME now return a syntax error when the FIELDS keyword is missing by @cjx-zar (#4300)
  • Fix a TLS and IO threads race that could leave slot migration export jobs stuck until timeout by @jjuleslasarte (#4320)
  • Fix a server crash when hash field expirations are set near the maximum timestamp, for example via HPEXPIREAT by @ranshid (#4312)
  • Fix a stack overflow crash on TLS connections when retrying a failed write of large replies by @murphyjacob4 (#4307)
  • Validate cluster bus PUBLISH and MODULE packet payload lengths, preventing a remote crash from forged length fields by @tjade273 (#3972)
  • Fix a use-after-free crash when serving blocked clients if handling one client frees another blocked on the same key by @quanyeyang (#4212)
  • Fix a server panic with IO threads when pipelined commands with a wrong number of arguments reached the key prefetcher by @madolson (#4302)
  • Reject crafted stream RESTORE and RDB payloads with inconsistent lengths or negative field counts that could crash the server by @madolson (#3922)
  • Reject stream payloads with mismatched live and deleted entry counts that could make XDEL destroy live entries by @roshkhatri (#4381)
  • Fix CLUSTER SLOT-STATS ORDERBY returning wrong ordering once cumulative slot counters differ by more than 2^31 by @jzy1688 (#4459)
  • Fix atomic slot migration failures with TLS and IO threads by not offloading export connection reads while snapshotting by @satheeshaGowda (#4559)

Full Changelog: https://github.com/valkey-io/valkey/compare/9.0.5...9.0.6

View originalPermalink
How 9.0.6 went

9.1.2

Fixed 18
  • Fix a double-free crash when a module timer callback stops its own timer with ValkeyModule_StopTimer
  • Fix torn RESP3 push frames when a client publishes to a channel it is also subscribed to
  • Listpacks are now always validated on RDB load and RESTORE, preventing deferred assertion crashes
  • Fix crashes, hangs, and CPU spinning when the RDMA transport is used together with I/O threads
  • RESET now clears the CLIENT IMPORT-SOURCE flag so reused pooled connections return to normal expiration semantics
  • Truncate a partially written MULTI block from the AOF on short read, preventing loss of newer writes after a later restart
Security 2
  • Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL
  • Fix an unauthenticated use-after-free of the Lua interpreter state caused by a process-global script debugger command table

From Valkey

Valkey 9.1.2 - Released Mon 31 August 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes
  • GHSA-jcj7-v34w-v9vv: Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL. Only affects servers built with USE_RDMA and configured with an RDMA listener (#4534)
  • GHSA-fq2f-crmw-q97r: Fix an unauthenticated use-after-free of the Lua interpreter state, caused by a process-global script debugger command table that cached a raw pointer to a freed interpreter and was never invalidated (#4574)
Bug Fixes
  • Fix a double-free crash when a module timer callback stops its own timer with ValkeyModule_StopTimer by @quanyeyang (#4211)
  • Fix torn RESP3 push frames when a client publishes to a channel it is also subscribed to, which could desync client libraries by @quanyeyang (#4253)
  • Listpacks are now always validated on RDB load and RESTORE, preventing deferred assertion crashes; sanitize-dump-payload and its ACL flags become no-ops by @jjuleslasarte (#3721)
  • Fix crashes, hangs, and CPU spinning when the RDMA transport is used together with I/O threads by @quanyeyang (#3611)
  • RESET now clears the CLIENT IMPORT-SOURCE flag, so reused pooled connections return to normal expiration semantics by @tjade273 (#3973)
  • Truncate a partially written MULTI block from the AOF on short read, preventing loss of newer writes after a later restart by @chzhoo (#4342)
  • Fix an ACL bypass where duplicate STORE/STOREDIST options let GEORADIUS write or delete keys outside the user's permitted patterns by @tjade273 (#3971)
  • Fix command log redaction leaking between commands in a MULTI transaction and missing for commands executed from scripts by @madolson (#4323)
  • Fix a use-after-free crash when a module's cluster message type is received after the module is unloaded by @enjoy-binbin (#4360)
  • Fix out-of-bounds access for cluster module message type 255, which is now a valid, dispatchable message type by @enjoy-binbin (#4410)
  • AOF loading no longer performs ACL checks on replayed commands, preventing silent data loss when the default user is disabled by @lukepalmer (#3984)
  • Fix a client memory accounting leak on replicas that inflated the mem_clients_normal INFO field after primary disconnections by @enjoy-binbin (#4395)
  • Fix a permanent client deadlock when a blocking command like BLPOP is followed by a partially delivered pipelined command by @foobar (#4531)
  • HGETEX now requires write permission on the key, closing an ACL gap that let read-only users change field TTLs or delete fields by @ranshid (#4576)
  • Compare the whole TLS certificate CN during authentication, so an embedded NUL can no longer impersonate another ACL user by @madolson (#4577)
  • Fix atomic slot migration failures with I/O threads by not offloading the export job's writes while snapshotting by @satheeshaGowda (#4104)
  • Reject invalid slot import ranges when loading an RDB, so corrupted files can no longer create bad migration jobs by @enjoy-binbin (#4229)
  • Reject RDB slot import records with an invalid job name length, preventing an out-of-bounds read at startup by @quanyeyang (#4210)
  • MOVE and COPY now check ACL access to the current database, so users can no longer exfiltrate keys from an unauthorized DB by @cjx-zar (#4155)
  • Fix a crash on COPY with a trailing DB option during slot migration, and block cross-DB COPY regardless of option order by @madolson (#4301)
  • Fix a server panic when pipelined commands with invalid arity reach the key prefetcher with I/O threads enabled by @madolson (#4302)
  • HPERSIST, HTTL, HPTTL, HEXPIRETIME, and HPEXPIRETIME now return a syntax error when the FIELDS keyword is missing by @cjx-zar (#4300)
  • Fix a race between TLS I/O-thread writes and reads that could leave slot migration export jobs stuck until timeout by @jjuleslasarte (#4320)
  • Fix a signed overflow that let very large hash field expiration times (e.g. via HPEXPIREAT) crash the server by @ranshid (#4312)
  • Fix a frozen monotonic clock on hosts with unsynchronized TSC that stopped background tasks and key expiration by @quanyeyang (#4346)
  • Fix a stack overflow crash when retrying a failed TLS write with a large reply by @murphyjacob4 (#4307)
  • Fix the --check-system clocksource check to skip hosts using a hardware clock and suggest only actually available clocksources by @quanyeyang (#4272)
  • Fix an assertion failure with I/O threads when a blocked client's pending command was processed again before unblocking by @quanyeyang (#4376)
  • Sentinel no longer loads the built-in Lua scripting engine, removing a spurious warning at startup by @enjoy-binbin (#4327)
  • Validate channel, message, and module payload lengths in cluster bus packets, preventing forged packets from crashing nodes by @tjade273 (#3972)
  • Harden stream validation on RDB load and RESTORE so crafted payloads can no longer crash the server on later commands by @madolson (#3922)
  • Reject stream payloads with mismatched live/deleted record counts, preventing XDEL from destroying unaccounted entries by @roshkhatri (#4381)
  • Skip unnecessary post-read processing with I/O threads on socket and TLS connections, restoring small-payload throughput by @quanyeyang (#4401)
  • Fix a use-after-free crash when serving clients blocked on the same key if one client is freed during processing by @quanyeyang (#4212)
  • Avoid an unneeded client lookup per write completion with I/O threads on socket and TLS connections, improving pipelined throughput by @dgershko (#4440)
  • Fix CLUSTER SLOT-STATS ORDERBY returning wrong ordering when slot counters differ by more than 2^31 by @jzy1688 (#4459)
  • Fix slot migration failures with I/O threads and TLS by keeping the export job's ACK reads on the main thread while snapshotting by @satheeshaGowda (#4559)

Full Changelog: https://github.com/valkey-io/valkey/compare/9.1.1...9.1.2

View originalPermalink
How 9.1.2 went

8.1.10

Fixed 14
  • Fix a double free when a module timer callback stops its own timer with ValkeyModule_StopTimer
  • RESET now clears the CLIENT IMPORT-SOURCE flag so reused pooled connections stop reading logically expired keys
  • Fix AOF recovery of a truncated MULTI/EXEC block that could cause new writes to be lost after a subsequent restart
  • Fix an ACL bypass where duplicate STORE/STOREDIST options in GEORADIUS commands escaped key write permission checks
  • Fix a use-after-free crash when a cluster message of a module-registered type arrives after the module is unloaded
  • Fix out-of-bounds access when registering or receiving cluster module messages of type 255
Deprecated 1
  • sanitize-dump-payload and the related ACL flags are now deprecated no-ops
Security 1
  • Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL on servers built with USE_RDMA and configured with an RDMA listener

From Valkey

Valkey 8.1.10 - Released Mon 31 August 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes
  • GHSA-jcj7-v34w-v9vv: Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL. Only affects servers built with USE_RDMA and configured with an RDMA listener (#4534)
Bug Fixes
  • Fix a double free when a module timer callback stops its own timer with ValkeyModule_StopTimer by @quanyeyang (#4211)
  • RESET now clears the CLIENT IMPORT-SOURCE flag so reused pooled connections stop reading logically expired keys by @tjade273 (#3973)
  • Fix AOF recovery of a truncated MULTI/EXEC block that could cause new writes to be lost after a subsequent restart by @chzhoo (#4342)
  • Fix an ACL bypass where duplicate STORE/STOREDIST options in GEORADIUS commands escaped key write permission checks by @tjade273 (#3971)
  • Fix a use-after-free crash when a cluster message of a module-registered type arrives after the module is unloaded by @enjoy-binbin (#4360)
  • Fix out-of-bounds access when registering or receiving cluster module messages of type 255, which is now fully supported by @enjoy-binbin (#4410)
  • Skip ACL permission checks when replaying the AOF, preventing silent data loss when users are restricted or disabled by @lukepalmer (#3984)
  • Fix a client memory accounting leak that inflated mem_clients_normal on replicas after disconnecting from the primary by @enjoy-binbin (#4395)
  • Always validate listpacks on RDB load and RESTORE to prevent deferred crashes; sanitize-dump-payload and the related ACL flags are now deprecated no-ops by @jjuleslasarte (#3721)
  • Fix a stack overflow crash when retrying large TLS writes after an OpenSSL write error by @murphyjacob4 (#4307)
  • Validate PUBLISH and MODULE cluster bus packet lengths, preventing a crash from forged packets with oversized payload lengths by @tjade273 (#3972)
  • Reject crafted stream RESTORE/RDB payloads with inconsistent lengths or negative field counts that could crash the server by @madolson (#3922)
  • Fix a use-after-free crash when serving multiple clients blocked on the same key if one is freed during processing by @quanyeyang (#4212)
  • Fix CLUSTER SLOT-STATS ORDERBY sorting when slot statistics differ by more than 2^31 by @jzy1688 (#4459)

Full Changelog: https://github.com/valkey-io/valkey/compare/8.1.9...8.1.10

View originalPermalink
How 8.1.10 went

8.0.11

Changed 1
  • Always deep-validate listpack payloads on RDB load and RESTORE, preventing deferred assertion crashes and deprecating sanitize-dump-payload which is now a no-op
Fixed 15
  • Fix a double-free crash when a module timer callback stops its own timer with ValkeyModule_StopTimer
  • Fix AOF truncation after a partially persisted MULTI/EXEC block so writes made after recovery are not lost on a later restart
  • Fix an ACL bypass where duplicate STORE/STOREDIST options in GEORADIUS commands let users write keys outside their permitted patterns
  • Fix a use-after-free crash when a cluster message for a module-registered type arrives after the module is unloaded
  • Fix out-of-bounds access on cluster module messages of type 255, which is now a valid message type
  • Fix silent data loss where ACL checks were wrongly applied to commands replayed from the AOF file
Security 1
  • Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL on servers built with USE_RDMA and configured with an RDMA listener

From Valkey

Valkey 8.0.11 - Released Mon 31 August 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes
  • GHSA-jcj7-v34w-v9vv: Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL. Only affects servers built with USE_RDMA and configured with an RDMA listener (#4534)
Bug Fixes
  • Fix a double-free crash when a module timer callback stops its own timer with ValkeyModule_StopTimer by @quanyeyang (#4211)
  • Fix AOF truncation after a partially persisted MULTI/EXEC block so writes made after recovery are not lost on a later restart by @chzhoo (#4342)
  • Fix an ACL bypass where duplicate STORE/STOREDIST options in GEORADIUS commands let users write keys outside their permitted patterns by @tjade273 (#3971)
  • Fix a use-after-free crash when a cluster message for a module-registered type arrives after the module is unloaded by @enjoy-binbin (#4360)
  • Fix out-of-bounds access on cluster module messages of type 255, which is now a valid message type by @enjoy-binbin (#4410)
  • Fix silent data loss where ACL checks were wrongly applied to commands replayed from the AOF file by @lukepalmer (#3984)
  • Fix a client memory accounting leak that inflated the mem_clients_normal INFO field on replicas by @enjoy-binbin (#4395)
  • Always deep-validate listpack payloads on RDB load and RESTORE, preventing deferred assertion crashes; sanitize-dump-payload is deprecated and now a no-op by @jjuleslasarte (#3721)
  • Fix module VM_Yield timing so repeated yields honor busy-reply-threshold instead of the server hz interval by @PingXie (#2131)
  • Fix a stack overflow crash when a large TLS write is retried after an OpenSSL write error by @murphyjacob4 (#4307)
  • Fix a crash caused by forged cluster bus PUBLISH or MODULE packets carrying oversized payload length fields by @tjade273 (#3972)
  • Reject crafted stream payloads in RDB load and RESTORE whose length or field-count metadata is inconsistent, preventing later server panics by @madolson (#3922)
  • Fix a cluster link disconnect loop after network failures that caused pub/sub messages between nodes to be lost by @dvkashapov (#2817)
  • Fix a use-after-free crash when a client blocked on a key is freed while other clients blocked on the same key are being served by @quanyeyang (#4212)
  • Reject crafted stream payloads that misstate live and deleted record counts, preventing data loss on XDEL by @roshkhatri (#4381)
  • Fix incorrect CLUSTER SLOT-STATS ORDERBY ordering when slot statistics differ by more than 2^31 by @jzy1688 (#4459)

Full Changelog: https://github.com/valkey-io/valkey/compare/8.0.10...8.0.11

View originalPermalink
How 8.0.11 went

9.1.1

Changed 1
  • Improve throughput when IO threads are enabled by offloading object deallocation from the main thread
Fixed 17
  • Omit the implicit alldbs ACL rule from ACL LIST, ACL SAVE and CONFIG REWRITE so older versions can parse the output
  • Fix use-after-free crash when ACL LOAD removes a user whose authenticated client has its close deferred
  • Enforce db= ACL permissions on every DB clause of COPY, closing a bypass with REPLACE or repeated DB tokens
  • Enforce database-level ACLs for CLUSTER FLUSHSLOT, which removes keys from all databases
  • Fix use-after-free in the module API when unregistering the first registered cluster message receiver
  • Fix HRANDFIELD with a positive count looping forever when non-expired fields are fewer than the requested count
Security 2
  • Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL
  • Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution

From Valkey

Valkey 9.1.1 - Released Tue 21 July 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes
  • CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
  • CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
  • Omit the implicit alldbs ACL rule from ACL LIST, ACL SAVE and CONFIG REWRITE so older versions can parse the output by @dvkashapov (#3964)
  • Improve throughput when IO threads are enabled by offloading object deallocation from the main thread by @roshkhatri (#3938)
  • Fix use-after-free crash when ACL LOAD removes a user whose authenticated client has its close deferred by @ranshid (#3800)
  • Enforce db= ACL permissions on every DB clause of COPY, closing a bypass with REPLACE or repeated DB tokens by @enjoy-binbin (#3801)
  • Enforce database-level ACLs for CLUSTER FLUSHSLOT, which removes keys from all databases by @enjoy-binbin (#3806)
  • Fix use-after-free in the module API when unregistering the first registered cluster message receiver by @eifrah-aws (#3846)
  • Fix HRANDFIELD with a positive count looping forever when non-expired fields are fewer than the requested count by @cjx-zar (#4047)
  • Fix clients left on the wrong database after module keyspace notifications for MOVE and COPY by @enjoy-binbin (#4024)
  • Fix Sentinel crash during coordinated failover when the command link to the old primary disconnects by @lukepalmer (#4068)
  • Fix crash when active hash field expiration leaves a single-entry expiry bucket whose last field is later removed by @ranshid (#3950)
  • Fix assertion in HEXPIRE, HGETDEL and HPERSIST when a module blocks the client in a keyspace notification callback by @enjoy-binbin (#3743)
  • Fix undefined behavior in the failover delay calculation when cluster-node-timeout is below 30 milliseconds by @enjoy-binbin (#3941)
  • Reject zipmap RESTORE/RDB payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
  • Reject NAN scores in listpack and ziplist encoded sorted sets on RDB/RESTORE load, preventing a crash on skiplist conversion by @madolson (#3921)
  • Fix corrupted replies (dropped leading bytes) caused by a reply buffer race when IO threads are enabled by @nanyan0312 (#4060)
  • Fix startup crash on 32-bit systems where time_t is 64-bit (such as Alpine 3.23) when generating INFO output by @chenshi5012 (#3787)
  • HGETDEL now returns a syntax error when the FIELDS keyword is missing or misplaced by @lcxn123 (#4049)
  • COMMAND INFO in RESP3 now returns the subcommands field as an array instead of a set for commands without subcommands by @rickrams (#3939)
  • Send the replica version on the dual-channel RDB connection so full syncs with newer encodings like hash field TTLs succeed by @hpatro (#4105)
  • Fix duplicate failure handling and an invalid reply sequence in cluster slot migration by @chx9 (#3723)
  • Reject control characters in SENTINEL SET values to prevent config-file injection via Sentinel config rewrite by @eifrah-aws (#3847)
  • Reject control characters and delimiters in cluster AUX fields and validate cluster-announce-ip to prevent nodes.conf injection by @eifrah-aws (#3848)
  • Redact key names and user data from more server log messages when hide-user-data-from-log is enabled by @zackcam (#3872)
  • ACL LOG now reports the denied database ID for COPY instead of the command name when db= access is denied by @enjoy-binbin (#3888)
  • Fix garbled shard IDs in the cluster UPDATE message log line by @enjoy-binbin (#3942)
  • Fix negative master_sync_total_bytes in INFO replication during disk-based sync when the RDB exceeds 2GB by @chx9 (#3811)
  • Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long paths by @pkhartsk (#3843)

Full Changelog: https://github.com/valkey-io/valkey/compare/9.1.0...9.1.1

View originalPermalink
How 9.1.1 went

9.0.5

Fixed 18
  • Strictly validate CRLF terminators when parsing the RESP protocol; malformed requests now get a protocol error instead of being misparsed
  • Fix a use-after-free crash when creating slot import jobs during manual slot migrations
  • Fix a memory leak in ZDIFF and ZDIFFSTORE when the result set becomes empty before all inputs are processed
  • Fix HPERSIST sending a malformed reply that desynchronized the connection when used on a key of the wrong type
  • Fix a crash from a race between IO threads and asynchronous client freeing
  • Fix a double free when loading a stream with corrupt consumer PEL data from RDB or RESTORE
Security 2
  • Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL
  • Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution

From Valkey

Valkey 9.0.5 - Released Tue 21 July 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes
  • CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
  • CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
  • Strictly validate CRLF terminators when parsing the RESP protocol; malformed requests now get a protocol error instead of being misparsed by @enjoy-binbin (#2872)
  • Fix a use-after-free crash when creating slot import jobs during manual slot migrations by @twooster (#3283)
  • Fix a memory leak in ZDIFF and ZDIFFSTORE when the result set becomes empty before all inputs are processed by @sarthakaggarwal97 (#3342)
  • Fix HPERSIST sending a malformed reply that desynchronized the connection when used on a key of the wrong type by @madolson (#3516)
  • Fix a crash from a race between IO threads and asynchronous client freeing by @deepakrn (#3458)
  • Fix a double free when loading a stream with corrupt consumer PEL data from RDB or RESTORE by @enjoy-binbin (#3498)
  • Fix listpack corruption and a subsequent crash when XTRIM marks the last entry of a stream listpack node as deleted by @smkher (#3591)
  • Fix malformed replies when module callbacks build deferred-length arrays while a client's deferred reply buffer is active by @eifrah-aws (#3578)
  • Fix a NULL pointer crash in TLS pending-data handling by @zuiderkwast (#3641)
  • Fix a server crash when multiple RDMA clients disconnect at the same time by @quanyeyang (#3448)
  • Fix a use-after-free when ACL LOAD deletes a user whose clients cannot be freed immediately by @ranshid (#3800)
  • Fix a use-after-free when a module unregisters the first registered cluster message receiver for a message type by @eifrah-aws (#3846)
  • Fix HRANDFIELD looping forever when a hash has fewer non-expired fields than the requested count by @cjx-zar (#4047)
  • Fix clients being left on the wrong database after module keyspace notifications for commands like MOVE and COPY by @enjoy-binbin (#4024)
  • Fix a Sentinel crash during coordinated failover when the connection to the old primary is disconnected by @lukepalmer (#4068)
  • Fix underestimation of client output buffer memory when replies reference shared objects, so buffer limits are enforced correctly by @dvkashapov (#3306)
  • Fix a crash on ARM/aarch64 caused by memory-ordering races in the IO thread job queue by @jjuleslasarte (#3878)
  • Fix a crash when active hash field expiration leaves a single entry in a large expiration time-bucket by @ranshid (#3950)
  • Fix a file descriptor leak when a blocking connection attempt, such as MIGRATE to an unreachable host, times out by @madolson (#3541)
  • Fix a potential crash from a dangling slot migration job reference when the migration client is reset by @murphyjacob4 (#3554)
  • Remove cached EVAL scripts when their scripting engine is unregistered, preventing dangling engine references by @eifrah-aws (#3503)
  • Fix a memory leak in GEOSEARCH BYPOLYGON when argument parsing fails, such as on an invalid COUNT by @bandalgomsu (#3568)
  • Fix a crash when a slot migration target node is removed from the cluster before the migration connects by @chenshi5012 (#3596)
  • Fix a crash when the module GetLRU/SetLRU/GetLFU/SetLFU APIs are called with a NULL key by @yaronsananes (#3610)
  • Fix an assertion failure in hash field expiration commands when a module blocks the client in a keyspace notification by @enjoy-binbin (#3743)
  • Fix a cluster UPDATE log message reading shard IDs past their fixed-length buffer by @enjoy-binbin (#3942)
  • Fix undefined behavior in the failover delay calculation when cluster-node-timeout is set below 30 milliseconds by @enjoy-binbin (#3941)
  • Reject zipmap RESTORE payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
  • Reject NAN scores in listpack- and ziplist-encoded sorted sets on RDB/RESTORE load, preventing a later crash on skiplist conversion by @madolson (#3921)
  • Fix a startup crash on 32-bit systems with 64-bit time_t, such as Alpine 3.23, caused by time value formatting mismatches by @chenshi5012 (#3787)
  • Fix corrupted client replies when IO threads are enabled, caused by a race between in-flight writes and reply buffer reuse by @nanyan0312 (#4060)
  • COMMAND INFO in RESP3 now returns the subcommands field as an Array instead of a Set for commands without subcommands by @rickrams (#3939)
  • The dual-channel replication RDB connection now announces the configured replica-announce-ip, avoiding stale replica entries behind NAT by @jdheyburn (#2846)
  • Prevent replicas from processing stale cluster packets and incorrectly promoting themselves to an empty primary within a shard by @zhijun42 (#2811)
  • Send the replica version on the dual-channel RDB connection so full syncs of data like hash field TTLs no longer fail by @hpatro (#4105)
  • Fix slot migration failure handling running twice on ownership changes and an out-of-order error reply in the internal SYNCSLOTS FINISH command by @chx9 (#3723)
  • Allow slot-migration-max-failover-repl-bytes to be set to -1 to disable the limit, as documented by @enjoy-binbin (#3443)
  • Fix CONFIG REWRITE producing negative values for memory configs such as maxmemory when set to very large values by @enjoy-binbin (#3440)
  • Reject SENTINEL SET values containing control characters and safely quote Sentinel config values to prevent config file injection by @eifrah-aws (#3847)
  • Reject control characters and delimiters in cluster AUX fields and validate cluster-announce-ip to prevent nodes.conf corruption or injection by @eifrah-aws (#3848)
  • Fix changes to lua-enable-insecure-api via CONFIG SET not taking effect when the option was set at startup by @enjoy-binbin (#4182)
  • Fix incorrect memory overhead reported for watched keys in client memory usage tracking by @enjoy-binbin (#3359)
  • Replica logs now report 'Connection reset by peer' instead of the misleading 'Success' when the primary closes the connection by @abmathur-ie (#3580)
  • Redact key names and user data from more log messages when hide-user-data-from-log is enabled by @zackcam (#3872)
  • Fix INFO replication reporting negative sync transfer sizes when the RDB exceeds 2GB during disk-based sync by @chx9 (#3811)
  • Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long installation paths by @pkhartsk (#3843)
  • valkey-cli --cluster del-node can now remove unreachable or failed nodes instead of failing with 'No such node ID' by @yang-z-o (#3209)
  • Fix valkey-cli crashing after --eval script execution on jemalloc/tcmalloc builds by @bandalgomsu (#3281)
  • valkey-cli --cluster fix now spreads uncovered slots randomly across primaries instead of assigning them all to one node by @abmathur-ie (#3586)

Full Changelog: https://github.com/valkey-io/valkey/compare/9.0.4...9.0.5

View originalPermalink
How 9.0.5 went

8.1.9

Changed 1
  • Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long installation paths
Fixed 8
  • Fix clients being left on the wrong database after module keyspace notifications from commands like MOVE and COPY
  • Fix an I/O thread job queue memory-ordering race that could trigger an assertion crash on ARM/aarch64
  • Reject zipmap RESTORE payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds
  • Reject NAN scores when loading listpack/ziplist-encoded sorted sets, preventing a crash from crafted RESTORE payloads
  • Fix a startup crash when generating INFO output on 32-bit systems where time_t is 64-bit (e.g. Alpine time64)
  • Fix COMMAND INFO in RESP3 to reply with an empty Array instead of a Set for commands without subcommands
  • Reject invalid characters in cluster AUX fields and cluster-announce-ip to prevent nodes.conf corruption and injection
  • Fix lua-enable-insecure-api having no effect when enabled at startup via config file or command line
Security 2
  • Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (CVE-2026-56684)
  • Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution (CVE-2026-63639)

From Valkey

Valkey 8.1.9 - Released Tue 21 July 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes
  • CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
  • CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
  • Fix clients being left on the wrong database after module keyspace notifications from commands like MOVE and COPY by @enjoy-binbin (#4024)
  • Fix an I/O thread job queue memory-ordering race that could trigger an assertion crash on ARM/aarch64 by @jjuleslasarte (#3878)
  • Reject zipmap RESTORE payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
  • Reject NAN scores when loading listpack/ziplist-encoded sorted sets, preventing a crash from crafted RESTORE payloads by @madolson (#3921)
  • Fix a startup crash when generating INFO output on 32-bit systems where time_t is 64-bit (e.g. Alpine time64) by @chenshi5012 (#3787)
  • Fix COMMAND INFO in RESP3 to reply with an empty Array instead of a Set for commands without subcommands by @rickrams (#3939)
  • Reject invalid characters in cluster AUX fields and cluster-announce-ip to prevent nodes.conf corruption and injection by @eifrah-aws (#3848)
  • Fix lua-enable-insecure-api having no effect when enabled at startup via config file or command line by @enjoy-binbin (#3548)
  • Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long installation paths by @pkhartsk (#3843)

Full Changelog: https://github.com/valkey-io/valkey/compare/8.1.8...8.1.9

View originalPermalink
How 8.1.9 went

8.0.10

Fixed 18
  • Strictly validate CRLF line endings when parsing the RESP protocol, rejecting malformed requests as protocol errors
  • Fix memory leak in ZDIFF/ZDIFFSTORE when the result set becomes empty before all input sets are processed
  • Fix crash caused by a race between asynchronous client freeing and IO threads reading from the closing client
  • Fix double free when loading corrupt stream RDB data containing duplicate consumer PEL entries
  • Fix stream corruption and crash when XTRIM marks the last entry of a listpack node as deleted
  • Fix potential crash in TLS pending-data handling when the connection has no SSL object
Security 2
  • Fix use-after-free in TLS connection handling that could allow an authenticated client to crash the server using CLIENT KILL
  • Reject corrupt stream RDB files containing a shared NACK across consumers

From Valkey

Valkey 8.0.10 - Released Tue 21 July 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes
  • CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to crash the server using CLIENT KILL (#4234)
  • CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
  • Strictly validate CRLF line endings when parsing the RESP protocol, rejecting malformed requests as protocol errors by @enjoy-binbin (#2872)
  • Fix memory leak in ZDIFF/ZDIFFSTORE when the result set becomes empty before all input sets are processed by @sarthakaggarwal97 (#3342)
  • Fix crash caused by a race between asynchronous client freeing and IO threads reading from the closing client by @deepakrn (#3458)
  • Fix double free when loading corrupt stream RDB data containing duplicate consumer PEL entries by @enjoy-binbin (#3498)
  • Fix stream corruption and crash when XTRIM marks the last entry of a listpack node as deleted by @smkher (#3591)
  • Fix potential crash in TLS pending-data handling when the connection has no SSL object by @zuiderkwast (#3641)
  • Fix use-after-free when ACL LOAD removes a user whose authenticated client's free is deferred by @ranshid (#3800)
  • Fix use-after-free when a module unregisters the first-registered cluster message receiver for a message type by @eifrah-aws (#3846)
  • Fix crash when loading functions after FUNCTION FLUSH ASYNC and make FUNCTION FLUSH actually release Lua VM memory by @enjoy-binbin (#1826)
  • Fix file descriptor leak when a blocking connect times out, such as MIGRATE to an unreachable host by @madolson (#3541)
  • Fix crash in module LRU/LFU API functions (GetLRU, SetLRU, GetLFU, SetLFU) when passed a NULL key by @yaronsananes (#3610)
  • TLS synchronous I/O no longer leaves a blocking socket in non-blocking mode, preventing unexpected short reads by @xbasel (#1298)
  • Fix crash when CLUSTER SLOTS is called without a real client connection, such as from a module timer callback by @bandalgomsu (#2915)
  • Fix assertion crash in the IO thread job queue on ARM/aarch64 caused by memory store reordering by @jjuleslasarte (#3878)
  • Reject zipmap RESTORE payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
  • Reject NAN scores in listpack and ziplist encoded sorted sets on RDB load, preventing a later crash on skiplist conversion by @madolson (#3921)
  • Fix crash on 32-bit systems where time_t is 64-bit (e.g. Alpine with time64) when generating INFO output by @chenshi5012 (#3787)
  • COMMAND INFO in RESP3 now returns an empty Array instead of a Set for the subcommands field of commands without subcommands by @rickrams (#3939)
  • Manual failover votes are no longer restricted by two times the node timeout, preventing manual failover timeouts by @enjoy-binbin (#1305)
  • Automatic failover votes are no longer restricted by two times the node timeout, matching the manual failover change by @enjoy-binbin (#1356)
  • SENTINEL SET now rejects values containing control characters and config rewrite escapes them, preventing config injection by @eifrah-aws (#3847)
  • Reject control characters and delimiters in cluster AUX fields and cluster-announce-ip to prevent nodes.conf injection by @eifrah-aws (#3848)
  • Fix lua-enable-insecure-api yes not taking effect when set at startup via config file or command line by @enjoy-binbin (#3548)
  • Log 'Connection reset by peer' instead of the misleading 'Success' when the connection to the primary closes during sync by @abmathur-ie (#3580)
  • Redact key names and user data from additional server log messages when hide-user-data-from-log is enabled by @zackcam (#3872)
  • Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long paths by @pkhartsk (#3843)
  • valkey-cli --cluster del-node can now remove unreachable or failed nodes instead of failing with 'No such node ID' by @yang-z-o (#3209)
  • Fix valkey-cli --cluster assigning all uncovered slots to the same primary instead of distributing them randomly by @abmathur-ie (#3586)

Full Changelog: https://github.com/valkey-io/valkey/compare/8.0.9...8.0.10

View originalPermalink
How 8.0.10 went

7.2.14

Fixed 17
  • Strictly check CRLF when parsing requests and reject malformed input as a protocol error instead of misparsing it
  • Fix a memory leak in ZDIFF and ZDIFFSTORE when the result set becomes empty during computation
  • Fix a double free when loading a stream consumer group from a corrupted RDB or RESTORE payload
  • Fix a potential crash from a NULL pointer dereference when updating the TLS pending-data flag
  • Fix a Lua VM crash when loading functions after FUNCTION FLUSH ASYNC and ensure flushed scripts' memory is released
  • Fix a use-after-free when a module unregisters and re-registers a cluster message receiver
Security 3
  • Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (CVE-2026-56684)
  • Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution (CVE-2026-63639)
  • Fix invalid memory access when loading a malformed zipmap payload via RESTORE (CVE-2026-25243)

From Valkey

Valkey 7.2.14 - Released Tue 21 July 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes
  • CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
  • CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
  • Strictly check CRLF when parsing requests and reject malformed input as a protocol error instead of misparsing it by @enjoy-binbin (#2872)
  • Fix a memory leak in ZDIFF and ZDIFFSTORE when the result set becomes empty during computation by @sarthakaggarwal97 (#3342)
  • Fix a double free when loading a stream consumer group from a corrupted RDB or RESTORE payload by @enjoy-binbin (#3498)
  • Fix a potential crash from a NULL pointer dereference when updating the TLS pending-data flag by @zuiderkwast (#3641)
  • Fix a Lua VM crash when loading functions after FUNCTION FLUSH ASYNC and ensure flushed scripts' memory is released by @enjoy-binbin (#1826)
  • Fix a use-after-free when a module unregisters and re-registers a cluster message receiver by @eifrah-aws (#3846)
  • Fix a file descriptor leak when a blocking connection attempt times out, e.g. during MIGRATE to an unreachable host by @madolson (#3541)
  • Fix a crash in the module API when VM_GetLRU, VM_SetLRU, VM_GetLFU, or VM_SetLFU is called with a NULL key by @yaronsananes (#3610)
  • Fix invalid memory access when loading a malformed zipmap payload via RESTORE (CVE-2026-25243) by @ranshid (#3619)
  • Reject zipmap payloads whose length fields overflow, which could cause out-of-bounds access on 32-bit platforms via RESTORE by @madolson (#3920)
  • Reject NAN scores in listpack and ziplist encoded sorted sets on RDB/RESTORE load, preventing a later server crash by @madolson (#3921)
  • Fix a startup crash when generating INFO output on 32-bit systems where time_t is 64-bit, such as Alpine 3.23 by @chenshi5012 (#3787)
  • Fix use of uninitialized memory when registering Lua functions with FUNCTION LOAD by @enjoy-binbin (#2750)
  • Fix listpack corruption and server crash when XTRIM marks the last entry in a stream listpack node as deleted by @smkher (#3591)
  • Fix COMMAND INFO returning the subcommands field as a RESP3 Set instead of an Array for commands without subcommands by @rickrams (#3939)
  • Reject control characters in SENTINEL SET values and escape them on config rewrite to prevent config-file injection by @eifrah-aws (#3847)
  • Reject control characters and unsafe delimiters in cluster AUX fields and cluster-announce-ip to prevent nodes.conf injection by @eifrah-aws (#3848)
  • Fix lua-enable-insecure-api having no effect when enabled at startup via the config file or command line by @enjoy-binbin (#3548)
  • Log the real error (e.g. Connection reset by peer) instead of the misleading Success on replication sync I/O errors by @abmathur-ie (#3580)
  • Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long paths by @pkhartsk (#3843)
  • Fix valkey-cli --cluster del-node failing with No such node ID when removing unreachable or failed nodes by @yang-z-o (#3209)
  • Fix valkey-cli --cluster fix assigning all uncovered slots to the same primary instead of spreading them randomly by @abmathur-ie (#3586)

Full Changelog: https://github.com/valkey-io/valkey/compare/7.2.13...7.2.14

View originalPermalink
How 7.2.14 went

8.1.8

Fixed 14
  • Fix ZDIFF algorithm 2 memory leak on early exit
  • Strictly check CRLF when parsing querybuf
  • Fix incorrect memory overhead calculation for watched keys
  • Fix valkey-cli --cluster del-node for unreachable nodes
  • Fix race condition during async client freeing with IO threading enabled
  • Fix double free in stream consumer PEL loading with corrupt RDB data
Security 2
  • Redact customer information when hide_user_data_from_log is true in rdb.c, networking.c, debug.c and t_hash
  • Harden SENTINEL commands and config rewrite against control-character injection

From Valkey

Upgrade urgency HIGH: There is a critical bug that may affect a subset of users.

Bug fixes

  • Fix ZDIFF algorithm 2 memory leak on early exit (#3342)
  • Strictly check CRLF when parsing querybuf (#2872)
  • Fix incorrect memory overhead calculation for watched keys (#3359)
  • Fix valkey-cli --cluster del-node for unreachable nodes (#3209)
  • Fix race condition during async client freeing with IO threading enabled (#3458)
  • Fix double free in stream consumer PEL loading with corrupt RDB data (#3498)
  • Fixes server crash when RDMA benchmark clients disconnect (#3448)
  • Fix misleading log "I/O error reading bulk count from PRIMARY: Success" (#3580)
  • Handle NULL pointer in streamTrim listpack delta calculation (#3591)
  • Fix Deferred Reply Placeholders in Active Deferred Buffers (#3578)
  • Add NULL check in updateSSLPendingFlag (#3641)
  • Fix heap-use-after-free in ACL LOAD when client free is deferred (#3800)
  • Redacting customer information when hide_user_data_from_log is true in rdb.c, networking.c, debug.c and t_hash (#3872)
  • Fix use-after-free in VM_RegisterClusterMessageReceiver (#3846)
  • Harden SENTINEL commands and config rewrite against control-character injection (#3847)
  • Fix CLUSTER SLOTS crash when called from module timer callback (#2915)

Full Changelog: https://github.com/valkey-io/valkey/compare/8.1.7...8.1.8

View originalPermalink
How 8.1.8 went

9.1.0

Added 1
  • Add cluster bus network traffic usage metric in bytes
Changed 1
  • Reduce latency spikes during rehashing via incremental page release
Fixed 5
  • Set errno on EOF in syncRead and propagate to conn->last
  • Fix GEOSEARCH BYPOLYGON leak on invalid COUNT
  • Handle NULL pointer in streamTrim listpack delta calculation
  • Fix server crash when RDMA benchmark clients disconnect
  • Fix memory leak in valkey-benchmark
Security 3
  • Fix use-after-free in unblock client flow (CVE-2026-23479)
  • Fix invalid memory access in RESTORE command (CVE-2026-25243)
  • Fix use-after-free when full sync occurs during a yielding Lua/function execution (CVE-2026-23631)

From Valkey

Upgrade urgency LOW: This is the first stable release of Valkey 9.1.

Security fixes
  • (CVE-2026-23479) Use-After-Free in unblock client flow
  • (CVE-2026-25243) Invalid Memory Access in RESTORE command
  • (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution
New Features and enhanced behavior
  • Add cluster bus network traffic usage metric in bytes by @hpatro (#3396)
  • Reduce latency spikes during rehashing via incremental page release by @chzhoo (#3481)
Bug Fixes
  • Fix(syncio): Set errno on EOF in syncRead and propagate to conn->last by @abmathur-ie (#3580)
  • Fix GEOSEARCH BYPOLYGON leak on invalid COUNT by @bandalgomsu (#3568)
  • Handle NULL pointer in streamTrim listpack delta calculation by @smkher (#3591)
  • Fixes server crash when RDMA benchmark clients disconnect by @quanyeyang (#3448)
  • Fix the memory leak in valkey-benchmark by @nmvk (#3643)

See also the release notes for 9.1.0-rc1 and 9.1.0-rc2.

View originalPermalink
How 9.1.0 went

8.0.9

Security 3
  • Fix use-after-free vulnerability in unblock client flow (CVE-2026-23479)
  • Fix invalid memory access vulnerability in RESTORE command (CVE-2026-25243)
  • Fix use-after-free vulnerability when full sync occurs during a yielding Lua/function execution (CVE-2026-23631)

From Valkey

Upgrade urgency SECURITY: This release supersedes 8.0.8 (revoked) and includes security fixes we recommend you apply as soon as possible.

Security fixes
  • (CVE-2026-23479) Use-After-Free in unblock client flow
  • (CVE-2026-25243) Invalid Memory Access in RESTORE command
  • (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution
View originalPermalink
How 8.0.9 went

8.1.7

Security 3
  • Fixed use-after-free in unblock client flow (CVE-2026-23479)
  • Fixed invalid memory access in RESTORE command (CVE-2026-25243)
  • Fixed use-after-free when full sync occurs during a yielding Lua/function execution (CVE-2026-23631)

From Valkey

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security fixes
  • (CVE-2026-23479) Use-After-Free in unblock client flow
  • (CVE-2026-25243) Invalid Memory Access in RESTORE command
  • (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution
View originalPermalink
How 8.1.7 went

9.0.4

Security 3
  • Fix use-after-free in unblock client flow (CVE-2026-23479)
  • Fix invalid memory access in RESTORE command (CVE-2026-25243)
  • Fix use-after-free when full sync occurs during a yielding Lua/function execution (CVE-2026-23631)

From Valkey

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security fixes
  • (CVE-2026-23479) Use-After-Free in unblock client flow
  • (CVE-2026-25243) Invalid Memory Access in RESTORE command
  • (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution
View originalPermalink
How 9.0.4 went
View all

Discussion

If you publish Valkey, you can claim this product by proving you administer its repository.