What changed in Valkey from 8 to 9
6 releases numbered after 8.1.10 up to and including 9.1.2, stable releases only. 8.1.10 and 9.1.2 are the newest stable releases of 8 and 9 we track; this page follows them as new ones ship.
- 5 CVEs mentioned
- 1 removes or deprecates something
- Spans branches 9.1, 9.0 — the list is by date, and a branch's own patches sit between the other's.
87 changes across 6 releases · 6 landed on more than one version
- Add cluster bus network traffic usage metric in bytes
- Fix crashes, assertion failures, and hangs when using RDMA together with IO threads
- Fix a double free when a module timer callback stops its own timer with ValkeyModule_StopTimer
- Fix torn RESP3 push frames when a client publishes a large message to a channel it is also subscribed to
- RESET now clears CLIENT IMPORT-SOURCE state so reused pooled connections regain normal key expiration semantics
- Truncated AOF files now discard an incomplete MULTI block entirely, preventing loss of later writes after another restart
- Fix an ACL bypass in GEORADIUS and GEORADIUSBYMEMBER where duplicate STORE options checked only the first destination key
- Fix a use-after-free crash when a cluster message arrives for a message type registered by an unloaded module
- Always deep-validate payloads on RDB load and RESTORE, preventing deferred assertion crashes
- Fix out-of-bounds memory access when registering or receiving cluster module messages of type 255
- AOF loading no longer applies ACL checks, preventing silent data loss when replaying commands with a disabled default user
- Fix a client memory accounting leak that inflated the mem_clients_normal INFO field on replicas after primary disconnects
- Fix a permanent client hang when a blocking command such as BLPOP is pipelined with a partially received next command
- HGETEX now requires write permission on the key, so read-only ACL users can no longer change field TTLs or delete fields
- Compare the full TLS certificate CN when authenticating, so an embedded NUL cannot impersonate a truncated ACL username
- Restore read performance with IO threads on TCP/TLS by applying extra read-completion handling only to RDMA connections
- Restore write performance with IO threads on TCP/TLS by limiting post-write safety checks to RDMA connections
- Fix atomic slot migration protocol errors with IO threads by not offloading export connection writes while snapshotting
- Reject invalid slot import ranges when loading an RDB, preventing corrupted files from creating bad migration state
- Fix a double-free crash when a module timer callback stops its own timer with ValkeyModule_StopTimer
- Fix torn RESP3 push frames when a client publishes to a channel it is also subscribed to
- Listpacks are now always validated on RDB load and RESTORE, preventing deferred assertion crashes
- Fix crashes, hangs, and CPU spinning when the RDMA transport is used together with I/O threads
- RESET now clears the CLIENT IMPORT-SOURCE flag so reused pooled connections return to normal expiration semantics
- Truncate a partially written MULTI block from the AOF on short read, preventing loss of newer writes after a later restart
- Fix an ACL bypass where duplicate STORE/STOREDIST options let GEORADIUS write or delete keys outside the user's permitted patterns
- Fix command log redaction leaking between commands in a MULTI transaction and missing for commands executed from scripts
- Fix a use-after-free crash when a module's cluster message type is received after the module is unloaded
- Fix out-of-bounds access for cluster module message type 255
- AOF loading no longer performs ACL checks on replayed commands, preventing silent data loss when the default user is disabled
- Fix a client memory accounting leak on replicas that inflated the mem_clients_normal INFO field after primary disconnections
- Fix a permanent client deadlock when a blocking command like BLPOP is followed by a partially delivered pipelined command
- HGETEX now requires write permission on the key, closing an ACL gap that let read-only users change field TTLs or delete fields
- Compare the whole TLS certificate CN during authentication so an embedded NUL can no longer impersonate another ACL user
- Fix atomic slot migration failures with I/O threads by not offloading the export job's writes while snapshotting
- Reject invalid slot import ranges when loading an RDB so corrupted files can no longer create bad migration jobs
- Reject RDB slot import records with an invalid job name length, preventing an out-of-bounds read at startup
- Omit the implicit alldbs ACL rule from ACL LIST, ACL SAVE and CONFIG REWRITE so older versions can parse the output
- Fix use-after-free crash when ACL LOAD removes a user whose authenticated client has its close deferred
- Enforce db= ACL permissions on every DB clause of COPY, closing a bypass with REPLACE or repeated DB tokens
- Enforce database-level ACLs for CLUSTER FLUSHSLOT, which removes keys from all databases
- Fix use-after-free in the module API when unregistering the first registered cluster message receiver
- Fix HRANDFIELD with a positive count looping forever when non-expired fields are fewer than the requested count
- Fix clients left on the wrong database after module keyspace notifications for MOVE and COPY
- Fix Sentinel crash during coordinated failover when the command link to the old primary disconnects
- Fix crash when active hash field expiration leaves a single-entry expiry bucket whose last field is later removed
- Fix assertion in HEXPIRE, HGETDEL and HPERSIST when a module blocks the client in a keyspace notification callback
- Fix undefined behavior in the failover delay calculation when cluster-node-timeout is below 30 milliseconds
- Reject zipmap RESTORE/RDB payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds
- Reject NAN scores in listpack and ziplist encoded sorted sets on RDB/RESTORE load, preventing a crash on skiplist conversion
- Fix corrupted replies caused by a reply buffer race when IO threads are enabled
- Fix startup crash on 32-bit systems where time_t is 64-bit when generating INFO output
- HGETDEL now returns a syntax error when the FIELDS keyword is missing or misplaced
- COMMAND INFO in RESP3 now returns the subcommands field as an array instead of a set for commands without subcommands
- Strictly validate CRLF terminators when parsing the RESP protocol; malformed requests now get a protocol error instead of being misparsed
- Fix a use-after-free crash when creating slot import jobs during manual slot migrations
- Fix a memory leak in ZDIFF and ZDIFFSTORE when the result set becomes empty before all inputs are processed
- Fix HPERSIST sending a malformed reply that desynchronized the connection when used on a key of the wrong type
- Fix a crash from a race between IO threads and asynchronous client freeing
- Fix a double free when loading a stream with corrupt consumer PEL data from RDB or RESTORE
- Fix listpack corruption and a subsequent crash when XTRIM marks the last entry of a stream listpack node as deleted
- Fix malformed replies when module callbacks build deferred-length arrays while a client's deferred reply buffer is active
- Fix a NULL pointer crash in TLS pending-data handling
- Fix a server crash when multiple RDMA clients disconnect at the same time
- Fix a use-after-free when ACL LOAD deletes a user whose clients cannot be freed immediately
- Fix a use-after-free when a module unregisters the first registered cluster message receiver for a message type
- Fix HRANDFIELD looping forever when a hash has fewer non-expired fields than the requested count
- Fix clients being left on the wrong database after module keyspace notifications for commands like MOVE and COPY
- Fix a Sentinel crash during coordinated failover when the connection to the old primary is disconnected
- Fix underestimation of client output buffer memory when replies reference shared objects, so buffer limits are enforced correctly
- Fix a crash on ARM/aarch64 caused by memory-ordering races in the IO thread job queue
- Fix a crash when active hash field expiration leaves a single entry in a large expiration time-bucket
- Set errno on EOF in syncRead and propagate to conn->last
- Fix GEOSEARCH BYPOLYGON leak on invalid COUNT
- Handle NULL pointer in streamTrim listpack delta calculation
- Fix server crash when RDMA benchmark clients disconnect
- Fix memory leak in valkey-benchmark
- sanitize-dump-payload is now a deprecated no-op
- Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILLalso in9.1.2
- Fix an unauthenticated use-after-free of the Lua interpreter state caused by a process-global script debugger command table
Original release notes, newest first
The list above is our reading of these notes; the originals from Linux Foundation are here, one fold per release.
9.0.6
Valkey 9.0.6 - Released Tue 01 September 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security Fixes
- GHSA-jcj7-v34w-v9vv: Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL. Only affects servers built with USE_RDMA and configured with an RDMA listener (#4534)
Bug Fixes
- Fix crashes, assertion failures, and hangs when using RDMA together with IO threads by @quanyeyang (#3335)
- Fix a double free when a module timer callback stops its own timer with ValkeyModule_StopTimer by @quanyeyang (#4211)
- Fix torn RESP3 push frames when a client publishes a large message to a channel it is also subscribed to by @quanyeyang (#4253)
- RESET now clears CLIENT IMPORT-SOURCE state so reused pooled connections regain normal key expiration semantics by @tjade273 (#3973)
- Truncated AOF files now discard an incomplete MULTI block entirely, preventing loss of later writes after another restart by @chzhoo (#4342)
- Fix an ACL bypass in GEORADIUS and GEORADIUSBYMEMBER where duplicate STORE options checked only the first destination key by @tjade273 (#3971)
- Fix a use-after-free crash when a cluster message arrives for a message type registered by an unloaded module by @enjoy-binbin (#4360)
- Always deep-validate payloads on RDB load and RESTORE, preventing deferred assertion crashes; sanitize-dump-payload is now a deprecated no-op by @jjuleslasarte (#3721)
- Fix out-of-bounds memory access when registering or receiving cluster module messages of type 255, which is now a valid type by @enjoy-binbin (#4410)
- AOF loading no longer applies ACL checks, preventing silent data loss when replaying commands with a disabled default user by @lukepalmer (#3984)
- Fix a client memory accounting leak that inflated the mem_clients_normal INFO field on replicas after primary disconnects by @enjoy-binbin (#4395)
- Fix a permanent client hang when a blocking command such as BLPOP is pipelined with a partially received next command by @foobar (#4531)
- HGETEX now requires write permission on the key, so read-only ACL users can no longer change field TTLs or delete fields by @ranshid (#4576)
- Compare the full TLS certificate CN when authenticating, so an embedded NUL cannot impersonate a truncated ACL username by @madolson (#4577)
- Restore read performance with IO threads on TCP/TLS by applying extra read-completion handling only to RDMA connections by @quanyeyang (#4414)
- Restore write performance with IO threads on TCP/TLS by limiting post-write safety checks to RDMA connections by @quanyeyang (#4452)
- Fix atomic slot migration protocol errors with IO threads by not offloading export connection writes while snapshotting by @satheeshaGowda (#4104)
- Reject invalid slot import ranges when loading an RDB, preventing corrupted files from creating bad migration state by @enjoy-binbin (#4229)
- Reject RDB slot-import records with an invalid job name length, fixing an out-of-bounds read during startup by @quanyeyang (#4210)
- Fix a crash when COPY ends with a bare DB token during slot migration, and block cross-DB COPY regardless of option order by @madolson (#4301)
- HPERSIST, HTTL, HPTTL, HEXPIRETIME, and HPEXPIRETIME now return a syntax error when the FIELDS keyword is missing by @cjx-zar (#4300)
- Fix a TLS and IO threads race that could leave slot migration export jobs stuck until timeout by @jjuleslasarte (#4320)
- Fix a server crash when hash field expirations are set near the maximum timestamp, for example via HPEXPIREAT by @ranshid (#4312)
- Fix a stack overflow crash on TLS connections when retrying a failed write of large replies by @murphyjacob4 (#4307)
- Validate cluster bus PUBLISH and MODULE packet payload lengths, preventing a remote crash from forged length fields by @tjade273 (#3972)
- Fix a use-after-free crash when serving blocked clients if handling one client frees another blocked on the same key by @quanyeyang (#4212)
- Fix a server panic with IO threads when pipelined commands with a wrong number of arguments reached the key prefetcher by @madolson (#4302)
- Reject crafted stream RESTORE and RDB payloads with inconsistent lengths or negative field counts that could crash the server by @madolson (#3922)
- Reject stream payloads with mismatched live and deleted entry counts that could make XDEL destroy live entries by @roshkhatri (#4381)
- Fix CLUSTER SLOT-STATS ORDERBY returning wrong ordering once cumulative slot counters differ by more than 2^31 by @jzy1688 (#4459)
- Fix atomic slot migration failures with TLS and IO threads by not offloading export connection reads while snapshotting by @satheeshaGowda (#4559)
Full Changelog: https://github.com/valkey-io/valkey/compare/9.0.5...9.0.6
9.1.2
Valkey 9.1.2 - Released Mon 31 August 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security Fixes
- GHSA-jcj7-v34w-v9vv: Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL. Only affects servers built with USE_RDMA and configured with an RDMA listener (#4534)
- GHSA-fq2f-crmw-q97r: Fix an unauthenticated use-after-free of the Lua interpreter state, caused by a process-global script debugger command table that cached a raw pointer to a freed interpreter and was never invalidated (#4574)
Bug Fixes
- Fix a double-free crash when a module timer callback stops its own timer with
ValkeyModule_StopTimerby @quanyeyang (#4211) - Fix torn RESP3 push frames when a client publishes to a channel it is also subscribed to, which could desync client libraries by @quanyeyang (#4253)
- Listpacks are now always validated on RDB load and RESTORE, preventing deferred assertion crashes;
sanitize-dump-payloadand its ACL flags become no-ops by @jjuleslasarte (#3721) - Fix crashes, hangs, and CPU spinning when the RDMA transport is used together with I/O threads by @quanyeyang (#3611)
- RESET now clears the
CLIENT IMPORT-SOURCEflag, so reused pooled connections return to normal expiration semantics by @tjade273 (#3973) - Truncate a partially written MULTI block from the AOF on short read, preventing loss of newer writes after a later restart by @chzhoo (#4342)
- Fix an ACL bypass where duplicate STORE/STOREDIST options let GEORADIUS write or delete keys outside the user's permitted patterns by @tjade273 (#3971)
- Fix command log redaction leaking between commands in a MULTI transaction and missing for commands executed from scripts by @madolson (#4323)
- Fix a use-after-free crash when a module's cluster message type is received after the module is unloaded by @enjoy-binbin (#4360)
- Fix out-of-bounds access for cluster module message type 255, which is now a valid, dispatchable message type by @enjoy-binbin (#4410)
- AOF loading no longer performs ACL checks on replayed commands, preventing silent data loss when the default user is disabled by @lukepalmer (#3984)
- Fix a client memory accounting leak on replicas that inflated the
mem_clients_normalINFO field after primary disconnections by @enjoy-binbin (#4395) - Fix a permanent client deadlock when a blocking command like BLPOP is followed by a partially delivered pipelined command by @foobar (#4531)
- HGETEX now requires write permission on the key, closing an ACL gap that let read-only users change field TTLs or delete fields by @ranshid (#4576)
- Compare the whole TLS certificate CN during authentication, so an embedded NUL can no longer impersonate another ACL user by @madolson (#4577)
- Fix atomic slot migration failures with I/O threads by not offloading the export job's writes while snapshotting by @satheeshaGowda (#4104)
- Reject invalid slot import ranges when loading an RDB, so corrupted files can no longer create bad migration jobs by @enjoy-binbin (#4229)
- Reject RDB slot import records with an invalid job name length, preventing an out-of-bounds read at startup by @quanyeyang (#4210)
- MOVE and COPY now check ACL access to the current database, so users can no longer exfiltrate keys from an unauthorized DB by @cjx-zar (#4155)
- Fix a crash on COPY with a trailing DB option during slot migration, and block cross-DB COPY regardless of option order by @madolson (#4301)
- Fix a server panic when pipelined commands with invalid arity reach the key prefetcher with I/O threads enabled by @madolson (#4302)
- HPERSIST, HTTL, HPTTL, HEXPIRETIME, and HPEXPIRETIME now return a syntax error when the FIELDS keyword is missing by @cjx-zar (#4300)
- Fix a race between TLS I/O-thread writes and reads that could leave slot migration export jobs stuck until timeout by @jjuleslasarte (#4320)
- Fix a signed overflow that let very large hash field expiration times (e.g. via HPEXPIREAT) crash the server by @ranshid (#4312)
- Fix a frozen monotonic clock on hosts with unsynchronized TSC that stopped background tasks and key expiration by @quanyeyang (#4346)
- Fix a stack overflow crash when retrying a failed TLS write with a large reply by @murphyjacob4 (#4307)
- Fix the
--check-systemclocksource check to skip hosts using a hardware clock and suggest only actually available clocksources by @quanyeyang (#4272) - Fix an assertion failure with I/O threads when a blocked client's pending command was processed again before unblocking by @quanyeyang (#4376)
- Sentinel no longer loads the built-in Lua scripting engine, removing a spurious warning at startup by @enjoy-binbin (#4327)
- Validate channel, message, and module payload lengths in cluster bus packets, preventing forged packets from crashing nodes by @tjade273 (#3972)
- Harden stream validation on RDB load and RESTORE so crafted payloads can no longer crash the server on later commands by @madolson (#3922)
- Reject stream payloads with mismatched live/deleted record counts, preventing XDEL from destroying unaccounted entries by @roshkhatri (#4381)
- Skip unnecessary post-read processing with I/O threads on socket and TLS connections, restoring small-payload throughput by @quanyeyang (#4401)
- Fix a use-after-free crash when serving clients blocked on the same key if one client is freed during processing by @quanyeyang (#4212)
- Avoid an unneeded client lookup per write completion with I/O threads on socket and TLS connections, improving pipelined throughput by @dgershko (#4440)
- Fix CLUSTER SLOT-STATS ORDERBY returning wrong ordering when slot counters differ by more than 2^31 by @jzy1688 (#4459)
- Fix slot migration failures with I/O threads and TLS by keeping the export job's ACK reads on the main thread while snapshotting by @satheeshaGowda (#4559)
Full Changelog: https://github.com/valkey-io/valkey/compare/9.1.1...9.1.2
9.1.1
Valkey 9.1.1 - Released Tue 21 July 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security Fixes
- CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
- CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
- Omit the implicit
alldbsACL rule fromACL LIST,ACL SAVEandCONFIG REWRITEso older versions can parse the output by @dvkashapov (#3964) - Improve throughput when IO threads are enabled by offloading object deallocation from the main thread by @roshkhatri (#3938)
- Fix use-after-free crash when
ACL LOADremoves a user whose authenticated client has its close deferred by @ranshid (#3800) - Enforce
db=ACL permissions on every DB clause ofCOPY, closing a bypass withREPLACEor repeated DB tokens by @enjoy-binbin (#3801) - Enforce database-level ACLs for
CLUSTER FLUSHSLOT, which removes keys from all databases by @enjoy-binbin (#3806) - Fix use-after-free in the module API when unregistering the first registered cluster message receiver by @eifrah-aws (#3846)
- Fix
HRANDFIELDwith a positive count looping forever when non-expired fields are fewer than the requested count by @cjx-zar (#4047) - Fix clients left on the wrong database after module keyspace notifications for
MOVEandCOPYby @enjoy-binbin (#4024) - Fix Sentinel crash during coordinated failover when the command link to the old primary disconnects by @lukepalmer (#4068)
- Fix crash when active hash field expiration leaves a single-entry expiry bucket whose last field is later removed by @ranshid (#3950)
- Fix assertion in
HEXPIRE,HGETDELandHPERSISTwhen a module blocks the client in a keyspace notification callback by @enjoy-binbin (#3743) - Fix undefined behavior in the failover delay calculation when
cluster-node-timeoutis below 30 milliseconds by @enjoy-binbin (#3941) - Reject zipmap RESTORE/RDB payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
- Reject NAN scores in listpack and ziplist encoded sorted sets on RDB/RESTORE load, preventing a crash on skiplist conversion by @madolson (#3921)
- Fix corrupted replies (dropped leading bytes) caused by a reply buffer race when IO threads are enabled by @nanyan0312 (#4060)
- Fix startup crash on 32-bit systems where time_t is 64-bit (such as Alpine 3.23) when generating
INFOoutput by @chenshi5012 (#3787) HGETDELnow returns a syntax error when theFIELDSkeyword is missing or misplaced by @lcxn123 (#4049)COMMAND INFOin RESP3 now returns the subcommands field as an array instead of a set for commands without subcommands by @rickrams (#3939)- Send the replica version on the dual-channel RDB connection so full syncs with newer encodings like hash field TTLs succeed by @hpatro (#4105)
- Fix duplicate failure handling and an invalid reply sequence in cluster slot migration by @chx9 (#3723)
- Reject control characters in
SENTINEL SETvalues to prevent config-file injection via Sentinel config rewrite by @eifrah-aws (#3847) - Reject control characters and delimiters in cluster AUX fields and validate
cluster-announce-ipto prevent nodes.conf injection by @eifrah-aws (#3848) - Redact key names and user data from more server log messages when
hide-user-data-from-logis enabled by @zackcam (#3872) ACL LOGnow reports the denied database ID forCOPYinstead of the command name whendb=access is denied by @enjoy-binbin (#3888)- Fix garbled shard IDs in the cluster UPDATE message log line by @enjoy-binbin (#3942)
- Fix negative
master_sync_total_bytesinINFO replicationduring disk-based sync when the RDB exceeds 2GB by @chx9 (#3811) - Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long paths by @pkhartsk (#3843)
Full Changelog: https://github.com/valkey-io/valkey/compare/9.1.0...9.1.1
9.0.5
Valkey 9.0.5 - Released Tue 21 July 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security Fixes
- CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
- CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
- Strictly validate CRLF terminators when parsing the RESP protocol; malformed requests now get a protocol error instead of being misparsed by @enjoy-binbin (#2872)
- Fix a use-after-free crash when creating slot import jobs during manual slot migrations by @twooster (#3283)
- Fix a memory leak in ZDIFF and ZDIFFSTORE when the result set becomes empty before all inputs are processed by @sarthakaggarwal97 (#3342)
- Fix HPERSIST sending a malformed reply that desynchronized the connection when used on a key of the wrong type by @madolson (#3516)
- Fix a crash from a race between IO threads and asynchronous client freeing by @deepakrn (#3458)
- Fix a double free when loading a stream with corrupt consumer PEL data from RDB or RESTORE by @enjoy-binbin (#3498)
- Fix listpack corruption and a subsequent crash when XTRIM marks the last entry of a stream listpack node as deleted by @smkher (#3591)
- Fix malformed replies when module callbacks build deferred-length arrays while a client's deferred reply buffer is active by @eifrah-aws (#3578)
- Fix a NULL pointer crash in TLS pending-data handling by @zuiderkwast (#3641)
- Fix a server crash when multiple RDMA clients disconnect at the same time by @quanyeyang (#3448)
- Fix a use-after-free when ACL LOAD deletes a user whose clients cannot be freed immediately by @ranshid (#3800)
- Fix a use-after-free when a module unregisters the first registered cluster message receiver for a message type by @eifrah-aws (#3846)
- Fix HRANDFIELD looping forever when a hash has fewer non-expired fields than the requested count by @cjx-zar (#4047)
- Fix clients being left on the wrong database after module keyspace notifications for commands like MOVE and COPY by @enjoy-binbin (#4024)
- Fix a Sentinel crash during coordinated failover when the connection to the old primary is disconnected by @lukepalmer (#4068)
- Fix underestimation of client output buffer memory when replies reference shared objects, so buffer limits are enforced correctly by @dvkashapov (#3306)
- Fix a crash on ARM/aarch64 caused by memory-ordering races in the IO thread job queue by @jjuleslasarte (#3878)
- Fix a crash when active hash field expiration leaves a single entry in a large expiration time-bucket by @ranshid (#3950)
- Fix a file descriptor leak when a blocking connection attempt, such as MIGRATE to an unreachable host, times out by @madolson (#3541)
- Fix a potential crash from a dangling slot migration job reference when the migration client is reset by @murphyjacob4 (#3554)
- Remove cached EVAL scripts when their scripting engine is unregistered, preventing dangling engine references by @eifrah-aws (#3503)
- Fix a memory leak in GEOSEARCH BYPOLYGON when argument parsing fails, such as on an invalid COUNT by @bandalgomsu (#3568)
- Fix a crash when a slot migration target node is removed from the cluster before the migration connects by @chenshi5012 (#3596)
- Fix a crash when the module GetLRU/SetLRU/GetLFU/SetLFU APIs are called with a NULL key by @yaronsananes (#3610)
- Fix an assertion failure in hash field expiration commands when a module blocks the client in a keyspace notification by @enjoy-binbin (#3743)
- Fix a cluster UPDATE log message reading shard IDs past their fixed-length buffer by @enjoy-binbin (#3942)
- Fix undefined behavior in the failover delay calculation when cluster-node-timeout is set below 30 milliseconds by @enjoy-binbin (#3941)
- Reject zipmap RESTORE payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
- Reject NAN scores in listpack- and ziplist-encoded sorted sets on RDB/RESTORE load, preventing a later crash on skiplist conversion by @madolson (#3921)
- Fix a startup crash on 32-bit systems with 64-bit time_t, such as Alpine 3.23, caused by time value formatting mismatches by @chenshi5012 (#3787)
- Fix corrupted client replies when IO threads are enabled, caused by a race between in-flight writes and reply buffer reuse by @nanyan0312 (#4060)
- COMMAND INFO in RESP3 now returns the subcommands field as an Array instead of a Set for commands without subcommands by @rickrams (#3939)
- The dual-channel replication RDB connection now announces the configured replica-announce-ip, avoiding stale replica entries behind NAT by @jdheyburn (#2846)
- Prevent replicas from processing stale cluster packets and incorrectly promoting themselves to an empty primary within a shard by @zhijun42 (#2811)
- Send the replica version on the dual-channel RDB connection so full syncs of data like hash field TTLs no longer fail by @hpatro (#4105)
- Fix slot migration failure handling running twice on ownership changes and an out-of-order error reply in the internal SYNCSLOTS FINISH command by @chx9 (#3723)
- Allow slot-migration-max-failover-repl-bytes to be set to -1 to disable the limit, as documented by @enjoy-binbin (#3443)
- Fix CONFIG REWRITE producing negative values for memory configs such as maxmemory when set to very large values by @enjoy-binbin (#3440)
- Reject SENTINEL SET values containing control characters and safely quote Sentinel config values to prevent config file injection by @eifrah-aws (#3847)
- Reject control characters and delimiters in cluster AUX fields and validate cluster-announce-ip to prevent nodes.conf corruption or injection by @eifrah-aws (#3848)
- Fix changes to lua-enable-insecure-api via CONFIG SET not taking effect when the option was set at startup by @enjoy-binbin (#4182)
- Fix incorrect memory overhead reported for watched keys in client memory usage tracking by @enjoy-binbin (#3359)
- Replica logs now report 'Connection reset by peer' instead of the misleading 'Success' when the primary closes the connection by @abmathur-ie (#3580)
- Redact key names and user data from more log messages when hide-user-data-from-log is enabled by @zackcam (#3872)
- Fix INFO replication reporting negative sync transfer sizes when the RDB exceeds 2GB during disk-based sync by @chx9 (#3811)
- Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long installation paths by @pkhartsk (#3843)
- valkey-cli --cluster del-node can now remove unreachable or failed nodes instead of failing with 'No such node ID' by @yang-z-o (#3209)
- Fix valkey-cli crashing after --eval script execution on jemalloc/tcmalloc builds by @bandalgomsu (#3281)
- valkey-cli --cluster fix now spreads uncovered slots randomly across primaries instead of assigning them all to one node by @abmathur-ie (#3586)
Full Changelog: https://github.com/valkey-io/valkey/compare/9.0.4...9.0.5
9.1.0
Upgrade urgency LOW: This is the first stable release of Valkey 9.1.
Security fixes
- (CVE-2026-23479) Use-After-Free in unblock client flow
- (CVE-2026-25243) Invalid Memory Access in RESTORE command
- (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution
New Features and enhanced behavior
- Add cluster bus network traffic usage metric in bytes by @hpatro (#3396)
- Reduce latency spikes during rehashing via incremental page release by @chzhoo (#3481)
Bug Fixes
- Fix(syncio): Set errno on EOF in syncRead and propagate to conn->last by @abmathur-ie (#3580)
- Fix GEOSEARCH BYPOLYGON leak on invalid COUNT by @bandalgomsu (#3568)
- Handle NULL pointer in streamTrim listpack delta calculation by @smkher (#3591)
- Fixes server crash when RDMA benchmark clients disconnect by @quanyeyang (#3448)
- Fix the memory leak in valkey-benchmark by @nmvk (#3643)
See also the release notes for 9.1.0-rc1 and 9.1.0-rc2.
9.0.4
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security fixes
- (CVE-2026-23479) Use-After-Free in unblock client flow
- (CVE-2026-25243) Invalid Memory Access in RESTORE command
- (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution