← Back to Resources
Open Source NewsAugust 17, 20262 min read

Redis Security Release: CVE-2026-62356 and Eight Related Fixes

By BIOS Founding Team

Redis Security Release: CVE-2026-62356 and Eight Related Fixes

Redis shipped coordinated security patches across every supported branch, addressing nine issues rated up to Critical. Highlights include a miscalculated buffer size in CMSketch RDB loading causing heap out-of-bounds write, and a TLS client-authentication bypass via a NUL byte embedded in a certificate's Common Name.

It also fixes multiple use-after-free bugs in TLS pending-data handling and blocked-client eviction. If you run Redis in production, this is worth upgrading to promptly.

Full details: https://github.com/redis/redis/releases/tag/8.10.1