Root cause
The researcher compared ordinary command handling with replication-related state changes during ongoing function execution. The latter did not preserve equivalent lifetime checks, so interpreter state could be released while still in use. The failed invariant was that background synchronization must not invalidate objects needed by active work.
Demonstrated impact
Code execution was demonstrated in the competition. The vendor limits exposure to authenticated access and replicas configured, or configurable, for writes. It reported Redis Cloud patched by its May 2026 announcement. These conditions do not establish equivalent exposure across all deployments.
Lessons for review
- Apply lifetime invariants to background synchronization and administrative state transitions as well as normal request paths.
- Treat reentrant event handling as a concurrency boundary even in a nominally single-threaded service.
- Review replica configuration and scripting privileges, and verify fixed versions against the vendor’s product-specific guidance.
Award and evidence
One individually identified competition entry. The organizer uses $; its current rules establish US-dollar notation but concern 2026, not an archived 2025 rules snapshot. Exact award decision and cash settlement are unknown.
Matched the individual award to the exact tracker CVE, researcher article and vendor credit. Cross-checked configuration prerequisites, CNA classification and the official release date.
- The tracker spells the researcher’s surname Sharez; the matching CVE, vendor credit and researcher article identify Yoni Sherez.
- The advisory’s structured affected field starts at 7.0.0 and says patched versions TBD, while its prose is broader; vendor guidance and the official release identify corrected versions. No universal version range is inferred.
- Competition code execution and vendor-qualified deployment exposure are distinct claims; the vendor says it had no evidence of customer exploitation at publication.
- Exact initial vendor-report, award-decision and cash-settlement dates are unknown. The June publication year is inferred.
- USD context comes from current organizer rules, explicitly distinct from an archived 2025 rules snapshot.
Recorded timeline
- Published
- 2026-06-02inferred · Article displays June 2; 2026 is inferred from its completed May 5, 2026 remediation timeline.
- Public Disclosure
- 2025-12-10explicit · Public competition demonstration; separate from later vendor advisory and technical publication.
- Fixed
- 2026-05-05explicit · Official Redis 8.6.3 release names the CVE. Other supported release lines are listed separately by the vendor; this date is not a customer deployment date.
- Award Announced
- 2025-12-16explicit · Organizer recap confirms the per-entry award; decision and payment dates remain unknown.
Sources and provenance
- ZeroDay.cloud 2025 individual competition results Nir Ohfeld / Wiz Research · reviewed 2026-10-02
- ZeroDay.cloud vulnerability tracker Wiz / ZeroDay.cloud · reviewed 2026-10-02
- ZeroDay.cloud current rules: US-dollar denomination Wiz · reviewed 2026-10-02
- DarkReplica (CVE-2026-23631): Redis Use-After-Free Leads to Post-Auth RCE Yoni Sherez / ZeroDay.cloud · reviewed 2026-10-02
- Redis Lua lifetime advisory GHSA-8ghh-qpmp-7826 Redis · reviewed 2026-10-02
- CVE-2026-23631 CNA record Redis / GitHub CNA · reviewed 2026-10-02
- Redis 8.6.3 security release Redis · reviewed 2026-10-02
- Redis May 2026 security advisory and product remediation table Riaz Lakhani / Redis · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.