vulns.co
/
GKData.io MCP

MEMemory safety and parser contracts · 3 min read

Redis replication state changes invalidated an active interpreter

Wiz confirms a USD 30,000 individual competition award for Yoni Sherez’s Redis entry, identified as CVE-2026-23631.

Read the primary source MEMemory safety and parser contractsReviewed 2026-10-02

Root cause

The researcher compared ordinary command handling with replication-related state changes during ongoing function execution. The latter did not preserve equivalent lifetime checks, so interpreter state could be released while still in use. The failed invariant was that background synchronization must not invalidate objects needed by active work.

Demonstrated impact

Code execution was demonstrated in the competition. The vendor limits exposure to authenticated access and replicas configured, or configurable, for writes. It reported Redis Cloud patched by its May 2026 announcement. These conditions do not establish equivalent exposure across all deployments.

Lessons for review

  • Apply lifetime invariants to background synchronization and administrative state transitions as well as normal request paths.
  • Treat reentrant event handling as a concurrency boundary even in a nominally single-threaded service.
  • Review replica configuration and scripting privileges, and verify fixed versions against the vendor’s product-specific guidance.

Award and evidence

USD 30,000Competition Award · Organizer Confirmed

One individually identified competition entry. The organizer uses $; its current rules establish US-dollar notation but concern 2026, not an archived 2025 rules snapshot. Exact award decision and cash settlement are unknown.

Matched the individual award to the exact tracker CVE, researcher article and vendor credit. Cross-checked configuration prerequisites, CNA classification and the official release date.

  • The tracker spells the researcher’s surname Sharez; the matching CVE, vendor credit and researcher article identify Yoni Sherez.
  • The advisory’s structured affected field starts at 7.0.0 and says patched versions TBD, while its prose is broader; vendor guidance and the official release identify corrected versions. No universal version range is inferred.
  • Competition code execution and vendor-qualified deployment exposure are distinct claims; the vendor says it had no evidence of customer exploitation at publication.
  • Exact initial vendor-report, award-decision and cash-settlement dates are unknown. The June publication year is inferred.
  • USD context comes from current organizer rules, explicitly distinct from an archived 2025 rules snapshot.

Recorded timeline

Published
2026-06-02inferred · Article displays June 2; 2026 is inferred from its completed May 5, 2026 remediation timeline.
Public Disclosure
2025-12-10explicit · Public competition demonstration; separate from later vendor advisory and technical publication.
Fixed
2026-05-05explicit · Official Redis 8.6.3 release names the CVE. Other supported release lines are listed separately by the vendor; this date is not a customer deployment date.
Award Announced
2025-12-16explicit · Organizer recap confirms the per-entry award; decision and payment dates remain unknown.

Sources and provenance

  1. ZeroDay.cloud 2025 individual competition results Nir Ohfeld / Wiz Research · reviewed 2026-10-02
  2. ZeroDay.cloud vulnerability tracker Wiz / ZeroDay.cloud · reviewed 2026-10-02
  3. ZeroDay.cloud current rules: US-dollar denomination Wiz · reviewed 2026-10-02
  4. DarkReplica (CVE-2026-23631): Redis Use-After-Free Leads to Post-Auth RCE Yoni Sherez / ZeroDay.cloud · reviewed 2026-10-02
  5. Redis Lua lifetime advisory GHSA-8ghh-qpmp-7826 Redis · reviewed 2026-10-02
  6. CVE-2026-23631 CNA record Redis / GitHub CNA · reviewed 2026-10-02
  7. Redis 8.6.3 security release Redis · reviewed 2026-10-02
  8. Redis May 2026 security advisory and product remediation table Riaz Lakhani / Redis · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software