valkey-io/valkey
 Watch   
 Star   
 Fork   
15 days ago
valkey

9.2.0-rc1

Valkey 9.2.0-rc1 - Released Wed 16 September 2026

Upgrade urgency LOW: This is the first release candidate of Valkey 9.2.0.

Behavior Changes

  • Active expiration of keys and hash fields now increments the dirty counter, so save points (and thus BGSAVE) may trigger more often by @enjoy-binbin (#3118)

New Features and Enhanced Behavior

  • Add ACL DIGEST command that returns a fingerprint of the ACL rules currently in effect, useful to verify what ACL LOAD applied by @melancholictheory (#4446)
  • Add forkless RDB snapshots, opt-in via the new forkless-infrastructure-enabled and bgsave-default-method configs, with new INFO persistence fields reporting the save method and progress by @JimB123 (#4460)
  • Add the XACKDEL and XDELEX stream commands with KEEPREF, DELREF and ACKED modes to acknowledge and delete messages once consumer groups no longer need them by @nickiaq (#4629)
  • Support a secondary server certificate via tls-alt-cert-file, tls-alt-key-file and tls-alt-key-file-pass, e.g. a post-quantum certificate alongside RSA, with matching INFO TLS fields by @pkhartsk (#3717)
  • Add ACL roles: named, reusable sets of ACL selectors managed with ACL SETROLE/DELROLE/GETROLE/ROLES and assigned to users with role:<name>, in commands, the ACL file and valkey.conf by @yang-z-o (#3967)
  • Add a maxmemory-scripts config to limit memory used by cached EVAL scripts, and mark SCRIPT LOAD as DENYOOM so it respects the global maxmemory limit by @enjoy-binbin (#866)
  • Add Path Hash, a new radix-tree-backed data type with PH* commands for exact lookup, longest-prefix matching, and prefix traversal over binary-safe paths by @yangbodong22011 (#4506)
  • Support whole-stream LZ4 compression of RDB files via the new rdbcompression lz4 option; the default per-string LZF behavior is unchanged by @sarthakaggarwal97 (#3531)
  • Add server-side hot key detection with new HOTKEYS GET/RESET commands, enabled by setting hotkeys-top-k by @alon-arenberg (#3708)
  • Add optional replication throttling (repl-throttling-enabled) that slows client writes when a replica falls behind, avoiding disconnects and full syncs by @harrylin98 (#4356)
  • Prioritize system-critical events (cluster heartbeats, replication, slot migration) over heavy client traffic, tunable via the new priority-preemptive-poll-interval-us config by @satheeshaGowda (#4076)
  • Reserve connection slots for administrative clients: connections from the CIDR ranges listed in the new priority-subnets config are tagged as prioritized, maxclients-reserved caps normal clients at maxclients minus that many slots, and INFO clients reports connected_priority_clients by @satheeshaGowda (#4005)
  • Add INCREX command to atomically increment a key by an integer or float while setting its expiration, with NX/XX conditions by @GavinDmello (#3253)

Performance and Efficiency Improvements

  • Speed up radix tree lookups and inserts by using SIMD-optimized memchr() for child-edge search by @charsyam (#3472)
  • Improve replica processing speed by parsing multiple commands from the replication stream at once by @enjoy-binbin (#3597)
  • Reduce memory usage by sharing pubsub pattern and WATCH key objects across clients subscribing to or watching the same name by @enjoy-binbin (#4072)
  • Large sorted sets are now backed by a B+ tree instead of a skiplist; OBJECT ENCODING reports btree instead of skiplist by @ranshid (#4359)
  • Save the cluster config file from a background thread when cluster-config-save-behavior is best-effort, avoiding main-thread latency spikes from slow disk I/O by @enjoy-binbin (#2555)
  • Speed up HMGET, SMISMEMBER and ZMSCORE on large hashtable-encoded keys with batched lookups that overlap memory accesses by @chzhoo (#4017)
  • Extend memory prefetching to hash, set and sorted set member lookups when io-threads are enabled, improving performance for 30 field/member commands on large keys by @roshkhatri (#3940)
  • MEMORY PURGE now also releases free pages from the glibc main arena back to the OS, reclaiming memory held by libc-internal allocations by @webbsssss (#3640)
  • Speed up command propagation to replicas by batching each command's RESP frame into a single replication buffer write by @hpatro (#4044)
  • Reduce lseek system calls during disk-based replication by seeking only when a write blocks or is partial by @enjoy-binbin (#4053)
  • Reduce event-loop overhead by refreshing cached daylight-saving info once per second instead of on every wakeup by @hpatro (#4086)
  • Speed up keyspace event notifications by skipping work when there are no subscribers and avoiding unnecessary allocations by @enjoy-binbin (#4285)
  • Speed up exact XTRIM MAXLEN = 0 by about 2.5x by clearing the whole stream in one step instead of removing entries individually by @sarthakaggarwal97 (#4161)
  • Cluster bus reads, writes, and inbound TLS accepts can now run on the shared I/O thread pool, with new CLUSTER INFO offload statistics by @hpatro (#3438)
  • Small hashes with field expiration now use the memory-efficient listpack encoding instead of always converting to a hashtable by @frostzt (#3212)
  • Reduce per-command overhead by skipping post-command bookkeeping when no propagation, module, or invalidation work is pending by @ahmetalicc (#4257)

Bug Fixes

  • MODULE LOAD is now rejected during async replication loading and atomic slot migration to avoid unexpected module behavior by @KIvanow (#3039)
  • Reject CLUSTER ADDSLOTS/DELSLOTS/ADDSLOTSRANGE/DELSLOTSRANGE/FLUSHSLOTS on replicas, preventing an assertion failure on a later CLUSTER REPLICATE by @enjoy-binbin (#4020)
  • Fix a crash when processing a heartbeat from a cluster node whose role is locally unknown, such as after loading an incomplete nodes.conf by @enjoy-binbin (#4091)
  • Fix wrong results or debug-build assertions in cluster mode when the server inspects keys outside the executing command's slot, such as WATCHed keys checked during EXEC by @nitaicaro (#4380)
  • Fix stream commands that mutate consumer-group or PEL state (XGROUP, XSETID, XREADGROUP, XACK, XCLAIM, XAUTOCLAIM) not triggering WATCH and client-side tracking invalidation by @Tarte12 (#3459)
  • Fix a server crash on FUNCTION DELETE or FUNCTION LOAD REPLACE after loading a library with function names differing only in case by @madolson (#3925)
  • Client-side tracking no longer records routing-only tokens such as the CLUSTERSCAN cursor as tracked keys by @nmvk (#3699)
  • Reject malformed slot entries in the cluster config file as a corrupt config instead of asserting or invoking undefined behavior by @enjoy-binbin (#4100)
  • Fix a TLS busy loop that consumed 100% CPU when a connection's read or write handler was removed while OpenSSL was waiting for the opposite event by @yairgott (#3510)
  • Client eviction no longer disconnects extra clients when a large client's close is deferred but its memory is already scheduled to be freed by @dhruv2x (#4152)
  • Fix a crash caused by a NULL pointer dereference when all timer events in an event loop are pending deletion by @royenheart (#4351)
  • Rework iteration over clients blocked on ready keys to simplify and harden an earlier use-after-free fix by @enjoy-binbin (#4472)
  • Fix a race in RDB string compression that could produce corrupt, unloadable RDB files when compression runs concurrently, without increasing copy-on-write by @dubey02 (#4539)
  • Fix dropped field TTLs and a possible crash when loading a hash with field expiration converts it to a hashtable mid-load (e.g. via RESTORE) by @madolson (#4669)
  • Reject a repeated CLUSTER SYNCSLOTS ESTABLISH on the same connection, which could lead to a use-after-free crash on disconnect by @Pyolar (#4670)
  • Fix wrong ZCOUNT results and incorrect ZREMRANGEBYSCORE deletions when members sharing a boundary score span multiple btree leaves by @rainsupreme (#4554)
  • Fix SORT key extraction so a STORE destination named like an option can no longer bypass ACL checks and write to an unauthorized key by @madolson (#4665)

Command and API Updates

  • MOVE accepts a new optional REPLACE argument to overwrite an existing key in the destination database by @bandalgomsu (#2993)
  • WAIT and WAITAOF now reject numreplicas values that are negative or exceed INT_MAX, fixing an integer overflow that broke blocking by @enjoy-binbin (#3407)
  • Add CONFIG INFO subcommand returning config metadata such as type, flags, valid enum values and numeric ranges by @nitaicaro (#3050)
  • Add the IFNE option to SET to set a key only when its current value differs from the given comparison value by @arshidkv12 (#3105)
  • Add IFEQ, IFNE, NX and XX conditions to EXEC, enabling optimistic locking for multi-key transactions without WATCH by @bandalgomsu (#4019)
  • Add an optional XX flag to SISMEMBER that returns -1 when the key does not exist, distinguishing a missing key from a missing member by @li-benson (#2972)
  • Handle NOT_KEY key-specs more defensively so COMMAND GETKEYS and ACL key checks consistently treat routing-only tokens as non-keys by @enjoy-binbin (#3675)
  • Fix DEBUG HELP to show the correct DELAY-RDB-CLIENT-FREE-SECONDS name and document the SET-DISABLE-DENY-SCRIPTS subcommand by @xiejing-dev (#4099)
  • Add XX option to the ZRANGE family of commands to distinguish a non-existent key (nil) from an empty result by @youngmore1024 (#2978)
  • Fix the reply schemas of the ZRANGE family of commands to allow the null reply returned with the XX option by @murphyjacob4 (#4275)
  • Fix the XPENDING reply schema to describe the summary reply returned when a consumer group has no pending messages by @sarthakaggarwal97 (#4653)

Cluster and Replication

  • Cluster replicas now redirect keyless commands like SCAN and FLUSHDB to the primary for clients with CAPA REDIRECT that have not sent READONLY by @yanamolo (#3505)
  • Changing cluster-require-full-coverage via CONFIG SET now updates the cluster state immediately instead of waiting for the next cron cycle by @enjoy-binbin (#3676)
  • Fix CLUSTER BUMPEPOCH getting stuck when a dead node holds an equal or abnormally high config epoch; a single bump now overtakes it by @enjoy-binbin (#4092)
  • Replicas now retry PSYNC when the primary replies -BUSY instead of downgrading to legacy SYNC, which broke WAIT, PSYNC and FAILOVER by @enjoy-binbin (#4140)
  • SYNC/PSYNC from a replica with a down primary link now consistently returns -NOMASTERLINK, avoiding an unnecessary full sync fallback by @enjoy-binbin (#4148)
  • Add cluster-replica-priority config so operators can rank which replicas are preferred during automatic cluster failover by @enjoy-binbin (#2204)
  • Speed up recovery from split-vote failover elections with a new FAILOVER_AUTH_NACK message that lets a replica detect an unwinnable election and immediately retry with a higher epoch by @enjoy-binbin (#3833)
  • Add optional per-target AUTH username password to CLUSTER MIGRATESLOTS, with credentials redacted from the slow log and MONITOR by @nemtsv (#3538)
  • Compress the full-sync RDB payload with LZ4 when rdbcompression lz4 is set and every attaching replica advertises support, reducing sync bandwidth with safe fallback to plaintext by @roshkhatri (#4075)
  • Add an if-empty value to cluster-replica-no-failover so a replica that has never received data from its primary refuses automatic failover, preventing silent data loss by @enjoy-binbin (#4425)
  • Add optional LZ4 streaming compression for steady-state replication via the new repl-compression config, negotiated per replica so older or opted-out replicas keep receiving plaintext by @roshkhatri (#3853)
  • Fix CLUSTERSCAN fingerprints to derive from the hash-seed config so cursors survive failover between nodes sharing a seed by @enjoy-binbin (#3679)
  • Replicas trigger a failover check immediately when cluster-replica-no-failover is disabled at runtime, instead of waiting for the next cron tick by @enjoy-binbin (#3827)
  • Validate node IDs and shard IDs received in cluster messages before applying them, dropping the link on invalid data to protect cluster state by @enjoy-binbin (#4065)
  • Drop the cluster link when a gossip section contains invalid node IDs, instead of keeping the connection to a corrupted sender alive by @enjoy-binbin (#4077)
  • Persist nodes.conf promptly when a node's address is updated through the gossip section by @enjoy-binbin (#4089)
  • Reject malformed node IDs in the open-slots RDB aux field instead of creating an illegal cluster node by @enjoy-binbin (#4098)
  • Strip the redundant LIMIT option when rewriting XADD/XTRIM for propagation, so the rewritten command is valid for tools that replay it by @cjx-zar (#4063)
  • Persist non-default cluster-replica-priority to nodes.conf so it survives restarts instead of waiting for the next gossip round by @enjoy-binbin (#4454)
  • Clear a stale primary-failure gossip flag on replicas so later failovers don't incorrectly skip the election delay by @charsyam (#4533)
  • Fix a node staying stuck in PFAIL when its PING is lost while the peer's own traffic keeps the cluster link alive by @enjoy-binbin (#4171)
  • CLUSTER SYNCSLOTS FINISH now rejects clients outside the slot migration stream, preventing misuse of the import state machine by @enjoy-binbin (#4330)

Configuration

  • commandlog-request-larger-than and commandlog-reply-larger-than now accept memory units such as 10mb by @enjoy-binbin (#2648)
  • cluster-announce-ip now must be a valid IP address or hostname, rejecting values like ip:port that broke cluster bus addressing by @AlisinaDevelo (#4055)
  • Reject an empty tls-ca-cert-dir at startup and CONFIG SET time instead of silently accepting it and failing every client handshake later by @yang-z-o (#3522)
  • Document the database-level ACL rules (db=, alldbs, resetdbs) in valkey.conf and clarify the reset rule description by @enjoy-binbin (#3808)
  • CONFIG REWRITE now preserves module load order, so modules with dependencies load correctly after a restart by @Taeknology (#3769)
  • Document in valkey.conf that unixsocketgroup requires the chown syscall to be allowed under syscall-filtering sandboxes by @moko-poi (#3730)

Module API Changes

  • Add ValkeyModule_ScanKeyRawBorrowed to scan hash, set and sorted set keys without allocating a string per element by @KarthikSubbarao (#4403)
  • Fix loading of legacy Redis modules that export RedisModule_OnLoad via a linker version script by @roshkhatri (#3374)
  • Module global defrag callbacks now receive a time limit and a resumable cursor, making ValkeyModule_RegisterDefragFunc usable for large module data by @Aksha1812 (#4487)
  • Add ValkeyModule_IncrExternalMemory/DecrExternalMemory so modules can report memory allocated outside the server allocator toward used_memory and maxmemory by @bandalgomsu (#4128)
  • Correct ValkeyModule_FreeModuleUser, ValkeyModule_ACLAddLogEntry and ValkeyModule_ACLAddLogEntryByUserName declarations to return int as implemented, fixing undefined behavior on targets with strict call signature checks by @rainsupreme (#4676)

Observability and Logging

  • Client memory usage now includes watched key and pubsub channel/pattern names, making it visible in CLIENT INFO tot-mem and counted for maxmemory-clients by @enjoy-binbin (#3362)
  • CONFIG RESETSTAT now also resets the IO-thread prefetch and ACL access-denied statistics by @enjoy-binbin (#2891)
  • Latency report now recommends 'madvise' for disabling Transparent Huge Pages, consistent with the startup check by @enjoy-binbin (#3947)
  • Log when a cluster primary ignores an MFSTART manual failover message from an unknown node or a non-replica, helping diagnose failover timeouts by @enjoy-binbin (#4058)
  • Log a warning when a TLS certificate has an invalid notBefore or notAfter field on OpenSSL 4.0 builds by @pkhartsk (#4064)
  • Gossip corruption warnings now log the actual entry with the invalid node ID instead of the first gossip entry by @enjoy-binbin (#4101)
  • Produce crash stack traces on musl-based systems like Alpine Linux via a libbacktrace fallback by @hanxizh9910 (#3581)
  • Always log the "possibly failing" notice when a node enters PFAIL, including on voting primaries by @enjoy-binbin (#4186)
  • EXEC transactions are now recorded in the slowlog and commandlog when their total execution time crosses the threshold by @michellee-10 (#4267)
  • Add last_successful_sync_duration_ms to INFO replication, reporting how long the replica's last full sync took by @satheeshaGowda (#4197)
  • Fix signal mask parsing on 32-bit systems so the crash handler can collect thread stack traces by @sarthakaggarwal97 (#4415)
  • Add total_cluster_links_established_inbound/outbound counters to CLUSTER INFO to help detect cluster link flapping by @enjoy-binbin (#4169)
  • RDMA connection and resource setup failures are now logged with detailed system error information by @quanyeyang (#4586)
  • Include the LRU list's duplicated script SHA copies in EVAL script memory reporting (used_memory_scripts_eval) by @enjoy-binbin (#4587)
  • Log the module version alongside the module name when a module is loaded, so the loaded version is visible in the log by @enjoy-binbin (#4566)
  • Detect changes to the alternate TLS key file (tls-alt-key-file) so certificate auto-reload picks them up by @pkhartsk (#4663)
  • Report tls_server_cert_serial and expiry INFO fields for the certificate actually loaded from tls-cert-file instead of whichever one OpenSSL slots first by @madolson (#4664)

CLI and Tools

  • valkey-cli reads the VALKEYCLI_HOST and VALKEYCLI_PORT environment variables to set the default host and port by @Dietr1ch (#3402)
  • valkey-benchmark can load CSV/TSV datasets and inject their fields into commands via __field:name__ placeholders by @VoletiRam (#2823)
  • valkey-cli supports the VALKEYCLI_USER environment variable as an alternative to the --user option by @jdheyburn (#4126)
  • valkey-cli --rdb now exits with an error instead of reporting success when trimming the RDB EOF marker fails, avoiding a silently corrupt file by @gluxier (#3945)
  • Fix valkey-benchmark crash (out-of-bounds read) when a repeat count is given with no command following it by @lightsigma96 (#4142)
  • valkey-benchmark -r now accepts keyspace sizes above INT_MAX (up to 999,999,999,999) with proper input validation by @michellee-10 (#4252)
  • valkey-benchmark now rejects a repeat count with no command after it with a clear error instead of hanging forever sending zero requests by @dhruv2x (#4215)
  • valkey-benchmark multi-threaded mode scales further by removing cross-thread contention in key generation, latency recording, and counters by @rainsupreme (#4332)

Build and Tooling

  • Add REUSE-compliant machine-readable licensing with per-file license clarity, enabling SPDX SBOM generation and correct license detection by @zuiderkwast (#3968)
  • Fix clean or highly parallel builds failing with a missing release.h for valkey-cli, valkey-benchmark, and unit tests by @poiuj (#3683)
  • Use PRIVATE link dependencies in CMake so Valkey's CMake files can be safely integrated into other projects by @eifrah-aws (#3658)
  • Pass CPPFLAGS to bundled dependencies and the src Makefile so packaging hardening flags apply to the whole build by @Vonng (#4318)
  • Raise the minimum required CMake version to 3.24 to match features already used by the build by @Baraa-Hasheesh (#4232)

Contributors

  • Abhishek Kumar @dubey02
  • abmathur-ie @abmathur-ie
  • Aditya Teltia @AdityaTeltia
  • Ahmad Belbeisi @ahmadbelb
  • Ahmet Alıç @ahmetalicc
  • Akash Kumar @akashkgit
  • AkshaThakkar1812 @Aksha1812
  • Alina Liu @asagege
  • Alisina Karimi @AlisinaDevelo
  • Alon Arenberg @alon-arenberg
  • Amariah Abishai @AmariahAK
  • Arshid @arshidkv12
  • Avi Fenesh @avifenesh
  • bandalgomsu @bandalgomsu
  • Bara' Hasheesh @Baraa-Hasheesh
  • Benson-li @li-benson
  • Binbin @enjoy-binbin
  • Björn Svensson @bjosv
  • bodong.ybd @yangbodong22011
  • Bonnie Chan @BChan-0
  • Brad Bebee @beebs-systap
  • charsyam @charsyam
  • chenshi @chenshi5012
  • chzhoo @chzhoo
  • cjx-zar @cjx-zar
  • Daejun Kim @djk1027
  • Daniil Kashapov @dvkashapov
  • Deepak Nandihalli @deepakrn
  • dgershko @dgershko
  • Dhruv Chauhan (chdh) @dhruv2x
  • Dietrich Daroch @Dietr1ch
  • Dragos Andriciuc @Andriciuc
  • eifrah-aws @eifrah-aws
  • FAN PEI @fanpei91
  • Feng Ruohang @Vonng
  • Gavin D'Mello @GavinDmello
  • gluxier @gluxier
  • Hanxi Zhang @hanxizh9910
  • Harkrishn Patro @hpatro
  • Harry Lin @harrylin98
  • hieu2102 @hieu2102
  • Jacob Murphy @murphyjacob4
  • Jeff Duffy @jaduffy
  • Jim Brunner @JimB123
  • jjuleslasarte @jjuleslasarte
  • Joe Heyburn @jdheyburn
  • Joseph Heck @heckj
  • Josh Soref @jsoref
  • Jun Yeong Kim @junyeong0619
  • justinfung @justinfung
  • jzy1688 @jzy1688
  • KarthikSubbarao @KarthikSubbarao
  • KimHuiSu @Tarte12
  • Kristiyan Ivanov @KIvanow
  • lcxn123 @lcxn123
  • lovelypiska @chx9
  • Lucas Yang @lucasyonge
  • Luke Palmer @lukepalmer
  • Madelyn Olson @madolson
  • martinrvisser @martinrvisser
  • Md Aakib Alam Ansari @0xAakibAlam
  • michellee-10 @michellee-10
  • nanyan @nanyan0312
  • Nick Iaquinto @nickiaq
  • Nikhil Manglore @Nikhil-Manglore
  • nitaicaro @nitaicaro
  • Ping Xie @PingXie
  • pkhartsk @pkhartsk
  • Quanye Yang @quanyeyang
  • Raghav Muddur @nmvk
  • Rain Valentine @rainsupreme
  • Ran Shidlansik @ranshid
  • Recoordinate @latent-9
  • Ricardo Dias @rjd15372
  • Rick Ramsay @rickrams
  • Roshan Khatri @roshkhatri
  • Sakshi Yadav @ydsakshi
  • sananes @yaronsananes
  • Sarthak Aggarwal @sarthakaggarwal97
  • Satheesha CH Gowda @satheeshaGowda
  • Saurabh K @smkher
  • secwall @secwall
  • Shun Takahashi @moko-poi
  • Smail KOURTA @skourta
  • Sourav Singh Rawat @frostzt
  • Stav Ben Shahar @stavBenShahar
  • Stefan Wang @1fanwang
  • sunliqiang @Pyolar
  • sushil paneru @sushilpaneru1
  • Taeknology @Taeknology
  • Tjaden Hess @tjade273
  • tomhanks @xiejing-dev
  • Tristan Su @foobar
  • Vadym Khoptynets @poiuj
  • Vaibhav Gupta @webbsssss
  • Vasiliy Koshkin @melancholictheory
  • Vasily Nemtsov @nemtsv
  • Viktor Söderqvist @zuiderkwast
  • VoletiRam @VoletiRam
  • Yair Gottdenker @yairgott
  • Yana Molodetsky @yanamolo
  • Yang Zhao @yang-z-o
  • Yash Jadhav @lightsigma96
  • youngmore1024 @youngmore1024
  • yulazariy @yulazariy
  • zackcam @zackcam
  • zhenwei pi @pizhenwei
  • Zhijun Liao @zhijun42
  • 皇心 @royenheart
2026-09-01 09:07:45
valkey

9.0.6

Valkey 9.0.6 - Released Tue 01 September 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes

  • GHSA-jcj7-v34w-v9vv: Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL. Only affects servers built with USE_RDMA and configured with an RDMA listener (#4534)

Bug Fixes

  • Fix crashes, assertion failures, and hangs when using RDMA together with IO threads by @quanyeyang (#3335)
  • Fix a double free when a module timer callback stops its own timer with ValkeyModule_StopTimer by @quanyeyang (#4211)
  • Fix torn RESP3 push frames when a client publishes a large message to a channel it is also subscribed to by @quanyeyang (#4253)
  • RESET now clears CLIENT IMPORT-SOURCE state so reused pooled connections regain normal key expiration semantics by @tjade273 (#3973)
  • Truncated AOF files now discard an incomplete MULTI block entirely, preventing loss of later writes after another restart by @chzhoo (#4342)
  • Fix an ACL bypass in GEORADIUS and GEORADIUSBYMEMBER where duplicate STORE options checked only the first destination key by @tjade273 (#3971)
  • Fix a use-after-free crash when a cluster message arrives for a message type registered by an unloaded module by @enjoy-binbin (#4360)
  • Always deep-validate payloads on RDB load and RESTORE, preventing deferred assertion crashes; sanitize-dump-payload is now a deprecated no-op by @jjuleslasarte (#3721)
  • Fix out-of-bounds memory access when registering or receiving cluster module messages of type 255, which is now a valid type by @enjoy-binbin (#4410)
  • AOF loading no longer applies ACL checks, preventing silent data loss when replaying commands with a disabled default user by @lukepalmer (#3984)
  • Fix a client memory accounting leak that inflated the mem_clients_normal INFO field on replicas after primary disconnects by @enjoy-binbin (#4395)
  • Fix a permanent client hang when a blocking command such as BLPOP is pipelined with a partially received next command by @foobar (#4531)
  • HGETEX now requires write permission on the key, so read-only ACL users can no longer change field TTLs or delete fields by @ranshid (#4576)
  • Compare the full TLS certificate CN when authenticating, so an embedded NUL cannot impersonate a truncated ACL username by @madolson (#4577)
  • Restore read performance with IO threads on TCP/TLS by applying extra read-completion handling only to RDMA connections by @quanyeyang (#4414)
  • Restore write performance with IO threads on TCP/TLS by limiting post-write safety checks to RDMA connections by @quanyeyang (#4452)
  • Fix atomic slot migration protocol errors with IO threads by not offloading export connection writes while snapshotting by @satheeshaGowda (#4104)
  • Reject invalid slot import ranges when loading an RDB, preventing corrupted files from creating bad migration state by @enjoy-binbin (#4229)
  • Reject RDB slot-import records with an invalid job name length, fixing an out-of-bounds read during startup by @quanyeyang (#4210)
  • Fix a crash when COPY ends with a bare DB token during slot migration, and block cross-DB COPY regardless of option order by @madolson (#4301)
  • HPERSIST, HTTL, HPTTL, HEXPIRETIME, and HPEXPIRETIME now return a syntax error when the FIELDS keyword is missing by @cjx-zar (#4300)
  • Fix a TLS and IO threads race that could leave slot migration export jobs stuck until timeout by @jjuleslasarte (#4320)
  • Fix a server crash when hash field expirations are set near the maximum timestamp, for example via HPEXPIREAT by @ranshid (#4312)
  • Fix a stack overflow crash on TLS connections when retrying a failed write of large replies by @murphyjacob4 (#4307)
  • Validate cluster bus PUBLISH and MODULE packet payload lengths, preventing a remote crash from forged length fields by @tjade273 (#3972)
  • Fix a use-after-free crash when serving blocked clients if handling one client frees another blocked on the same key by @quanyeyang (#4212)
  • Fix a server panic with IO threads when pipelined commands with a wrong number of arguments reached the key prefetcher by @madolson (#4302)
  • Reject crafted stream RESTORE and RDB payloads with inconsistent lengths or negative field counts that could crash the server by @madolson (#3922)
  • Reject stream payloads with mismatched live and deleted entry counts that could make XDEL destroy live entries by @roshkhatri (#4381)
  • Fix CLUSTER SLOT-STATS ORDERBY returning wrong ordering once cumulative slot counters differ by more than 2^31 by @jzy1688 (#4459)
  • Fix atomic slot migration failures with TLS and IO threads by not offloading export connection reads while snapshotting by @satheeshaGowda (#4559)

Full Changelog: https://github.com/valkey-io/valkey/compare/9.0.5...9.0.6

2026-09-01 07:40:24
valkey

9.1.2

Valkey 9.1.2 - Released Mon 31 August 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes

  • GHSA-jcj7-v34w-v9vv: Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL. Only affects servers built with USE_RDMA and configured with an RDMA listener (#4534)
  • GHSA-fq2f-crmw-q97r: Fix an unauthenticated use-after-free of the Lua interpreter state, caused by a process-global script debugger command table that cached a raw pointer to a freed interpreter and was never invalidated (#4574)

Bug Fixes

  • Fix a double-free crash when a module timer callback stops its own timer with ValkeyModule_StopTimer by @quanyeyang (#4211)
  • Fix torn RESP3 push frames when a client publishes to a channel it is also subscribed to, which could desync client libraries by @quanyeyang (#4253)
  • Listpacks are now always validated on RDB load and RESTORE, preventing deferred assertion crashes; sanitize-dump-payload and its ACL flags become no-ops by @jjuleslasarte (#3721)
  • Fix crashes, hangs, and CPU spinning when the RDMA transport is used together with I/O threads by @quanyeyang (#3611)
  • RESET now clears the CLIENT IMPORT-SOURCE flag, so reused pooled connections return to normal expiration semantics by @tjade273 (#3973)
  • Truncate a partially written MULTI block from the AOF on short read, preventing loss of newer writes after a later restart by @chzhoo (#4342)
  • Fix an ACL bypass where duplicate STORE/STOREDIST options let GEORADIUS write or delete keys outside the user's permitted patterns by @tjade273 (#3971)
  • Fix command log redaction leaking between commands in a MULTI transaction and missing for commands executed from scripts by @madolson (#4323)
  • Fix a use-after-free crash when a module's cluster message type is received after the module is unloaded by @enjoy-binbin (#4360)
  • Fix out-of-bounds access for cluster module message type 255, which is now a valid, dispatchable message type by @enjoy-binbin (#4410)
  • AOF loading no longer performs ACL checks on replayed commands, preventing silent data loss when the default user is disabled by @lukepalmer (#3984)
  • Fix a client memory accounting leak on replicas that inflated the mem_clients_normal INFO field after primary disconnections by @enjoy-binbin (#4395)
  • Fix a permanent client deadlock when a blocking command like BLPOP is followed by a partially delivered pipelined command by @foobar (#4531)
  • HGETEX now requires write permission on the key, closing an ACL gap that let read-only users change field TTLs or delete fields by @ranshid (#4576)
  • Compare the whole TLS certificate CN during authentication, so an embedded NUL can no longer impersonate another ACL user by @madolson (#4577)
  • Fix atomic slot migration failures with I/O threads by not offloading the export job's writes while snapshotting by @satheeshaGowda (#4104)
  • Reject invalid slot import ranges when loading an RDB, so corrupted files can no longer create bad migration jobs by @enjoy-binbin (#4229)
  • Reject RDB slot import records with an invalid job name length, preventing an out-of-bounds read at startup by @quanyeyang (#4210)
  • MOVE and COPY now check ACL access to the current database, so users can no longer exfiltrate keys from an unauthorized DB by @cjx-zar (#4155)
  • Fix a crash on COPY with a trailing DB option during slot migration, and block cross-DB COPY regardless of option order by @madolson (#4301)
  • Fix a server panic when pipelined commands with invalid arity reach the key prefetcher with I/O threads enabled by @madolson (#4302)
  • HPERSIST, HTTL, HPTTL, HEXPIRETIME, and HPEXPIRETIME now return a syntax error when the FIELDS keyword is missing by @cjx-zar (#4300)
  • Fix a race between TLS I/O-thread writes and reads that could leave slot migration export jobs stuck until timeout by @jjuleslasarte (#4320)
  • Fix a signed overflow that let very large hash field expiration times (e.g. via HPEXPIREAT) crash the server by @ranshid (#4312)
  • Fix a frozen monotonic clock on hosts with unsynchronized TSC that stopped background tasks and key expiration by @quanyeyang (#4346)
  • Fix a stack overflow crash when retrying a failed TLS write with a large reply by @murphyjacob4 (#4307)
  • Fix the --check-system clocksource check to skip hosts using a hardware clock and suggest only actually available clocksources by @quanyeyang (#4272)
  • Fix an assertion failure with I/O threads when a blocked client's pending command was processed again before unblocking by @quanyeyang (#4376)
  • Sentinel no longer loads the built-in Lua scripting engine, removing a spurious warning at startup by @enjoy-binbin (#4327)
  • Validate channel, message, and module payload lengths in cluster bus packets, preventing forged packets from crashing nodes by @tjade273 (#3972)
  • Harden stream validation on RDB load and RESTORE so crafted payloads can no longer crash the server on later commands by @madolson (#3922)
  • Reject stream payloads with mismatched live/deleted record counts, preventing XDEL from destroying unaccounted entries by @roshkhatri (#4381)
  • Skip unnecessary post-read processing with I/O threads on socket and TLS connections, restoring small-payload throughput by @quanyeyang (#4401)
  • Fix a use-after-free crash when serving clients blocked on the same key if one client is freed during processing by @quanyeyang (#4212)
  • Avoid an unneeded client lookup per write completion with I/O threads on socket and TLS connections, improving pipelined throughput by @dgershko (#4440)
  • Fix CLUSTER SLOT-STATS ORDERBY returning wrong ordering when slot counters differ by more than 2^31 by @jzy1688 (#4459)
  • Fix slot migration failures with I/O threads and TLS by keeping the export job's ACK reads on the main thread while snapshotting by @satheeshaGowda (#4559)

Full Changelog: https://github.com/valkey-io/valkey/compare/9.1.1...9.1.2

2026-09-01 07:23:17
valkey

8.0.11

Valkey 8.0.11 - Released Mon 31 August 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes

  • GHSA-jcj7-v34w-v9vv: Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL. Only affects servers built with USE_RDMA and configured with an RDMA listener (#4534)

Bug Fixes

  • Fix a double-free crash when a module timer callback stops its own timer with ValkeyModule_StopTimer by @quanyeyang (#4211)
  • Fix AOF truncation after a partially persisted MULTI/EXEC block so writes made after recovery are not lost on a later restart by @chzhoo (#4342)
  • Fix an ACL bypass where duplicate STORE/STOREDIST options in GEORADIUS commands let users write keys outside their permitted patterns by @tjade273 (#3971)
  • Fix a use-after-free crash when a cluster message for a module-registered type arrives after the module is unloaded by @enjoy-binbin (#4360)
  • Fix out-of-bounds access on cluster module messages of type 255, which is now a valid message type by @enjoy-binbin (#4410)
  • Fix silent data loss where ACL checks were wrongly applied to commands replayed from the AOF file by @lukepalmer (#3984)
  • Fix a client memory accounting leak that inflated the mem_clients_normal INFO field on replicas by @enjoy-binbin (#4395)
  • Always deep-validate listpack payloads on RDB load and RESTORE, preventing deferred assertion crashes; sanitize-dump-payload is deprecated and now a no-op by @jjuleslasarte (#3721)
  • Fix module VM_Yield timing so repeated yields honor busy-reply-threshold instead of the server hz interval by @PingXie (#2131)
  • Fix a stack overflow crash when a large TLS write is retried after an OpenSSL write error by @murphyjacob4 (#4307)
  • Fix a crash caused by forged cluster bus PUBLISH or MODULE packets carrying oversized payload length fields by @tjade273 (#3972)
  • Reject crafted stream payloads in RDB load and RESTORE whose length or field-count metadata is inconsistent, preventing later server panics by @madolson (#3922)
  • Fix a cluster link disconnect loop after network failures that caused pub/sub messages between nodes to be lost by @dvkashapov (#2817)
  • Fix a use-after-free crash when a client blocked on a key is freed while other clients blocked on the same key are being served by @quanyeyang (#4212)
  • Reject crafted stream payloads that misstate live and deleted record counts, preventing data loss on XDEL by @roshkhatri (#4381)
  • Fix incorrect CLUSTER SLOT-STATS ORDERBY ordering when slot statistics differ by more than 2^31 by @jzy1688 (#4459)

Full Changelog: https://github.com/valkey-io/valkey/compare/8.0.10...8.0.11

2026-09-01 07:14:29
valkey

8.1.10

Valkey 8.1.10 - Released Mon 31 August 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes

  • GHSA-jcj7-v34w-v9vv: Fix a use-after-free in RDMA connection handling that could allow an authenticated client to crash the server using CLIENT KILL. Only affects servers built with USE_RDMA and configured with an RDMA listener (#4534)

Bug Fixes

  • Fix a double free when a module timer callback stops its own timer with ValkeyModule_StopTimer by @quanyeyang (#4211)
  • RESET now clears the CLIENT IMPORT-SOURCE flag so reused pooled connections stop reading logically expired keys by @tjade273 (#3973)
  • Fix AOF recovery of a truncated MULTI/EXEC block that could cause new writes to be lost after a subsequent restart by @chzhoo (#4342)
  • Fix an ACL bypass where duplicate STORE/STOREDIST options in GEORADIUS commands escaped key write permission checks by @tjade273 (#3971)
  • Fix a use-after-free crash when a cluster message of a module-registered type arrives after the module is unloaded by @enjoy-binbin (#4360)
  • Fix out-of-bounds access when registering or receiving cluster module messages of type 255, which is now fully supported by @enjoy-binbin (#4410)
  • Skip ACL permission checks when replaying the AOF, preventing silent data loss when users are restricted or disabled by @lukepalmer (#3984)
  • Fix a client memory accounting leak that inflated mem_clients_normal on replicas after disconnecting from the primary by @enjoy-binbin (#4395)
  • Always validate listpacks on RDB load and RESTORE to prevent deferred crashes; sanitize-dump-payload and the related ACL flags are now deprecated no-ops by @jjuleslasarte (#3721)
  • Fix a stack overflow crash when retrying large TLS writes after an OpenSSL write error by @murphyjacob4 (#4307)
  • Validate PUBLISH and MODULE cluster bus packet lengths, preventing a crash from forged packets with oversized payload lengths by @tjade273 (#3972)
  • Reject crafted stream RESTORE/RDB payloads with inconsistent lengths or negative field counts that could crash the server by @madolson (#3922)
  • Fix a use-after-free crash when serving multiple clients blocked on the same key if one is freed during processing by @quanyeyang (#4212)
  • Fix CLUSTER SLOT-STATS ORDERBY sorting when slot statistics differ by more than 2^31 by @jzy1688 (#4459)

Full Changelog: https://github.com/valkey-io/valkey/compare/8.1.9...8.1.10

2026-07-22 07:39:06
valkey

9.0.5

Valkey 9.0.5 - Released Tue 21 July 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes

  • CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
  • CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)

Bug Fixes

  • Strictly validate CRLF terminators when parsing the RESP protocol; malformed requests now get a protocol error instead of being misparsed by @enjoy-binbin (#2872)
  • Fix a use-after-free crash when creating slot import jobs during manual slot migrations by @twooster (#3283)
  • Fix a memory leak in ZDIFF and ZDIFFSTORE when the result set becomes empty before all inputs are processed by @sarthakaggarwal97 (#3342)
  • Fix HPERSIST sending a malformed reply that desynchronized the connection when used on a key of the wrong type by @madolson (#3516)
  • Fix a crash from a race between IO threads and asynchronous client freeing by @deepakrn (#3458)
  • Fix a double free when loading a stream with corrupt consumer PEL data from RDB or RESTORE by @enjoy-binbin (#3498)
  • Fix listpack corruption and a subsequent crash when XTRIM marks the last entry of a stream listpack node as deleted by @smkher (#3591)
  • Fix malformed replies when module callbacks build deferred-length arrays while a client's deferred reply buffer is active by @eifrah-aws (#3578)
  • Fix a NULL pointer crash in TLS pending-data handling by @zuiderkwast (#3641)
  • Fix a server crash when multiple RDMA clients disconnect at the same time by @quanyeyang (#3448)
  • Fix a use-after-free when ACL LOAD deletes a user whose clients cannot be freed immediately by @ranshid (#3800)
  • Fix a use-after-free when a module unregisters the first registered cluster message receiver for a message type by @eifrah-aws (#3846)
  • Fix HRANDFIELD looping forever when a hash has fewer non-expired fields than the requested count by @cjx-zar (#4047)
  • Fix clients being left on the wrong database after module keyspace notifications for commands like MOVE and COPY by @enjoy-binbin (#4024)
  • Fix a Sentinel crash during coordinated failover when the connection to the old primary is disconnected by @lukepalmer (#4068)
  • Fix underestimation of client output buffer memory when replies reference shared objects, so buffer limits are enforced correctly by @dvkashapov (#3306)
  • Fix a crash on ARM/aarch64 caused by memory-ordering races in the IO thread job queue by @jjuleslasarte (#3878)
  • Fix a crash when active hash field expiration leaves a single entry in a large expiration time-bucket by @ranshid (#3950)
  • Fix a file descriptor leak when a blocking connection attempt, such as MIGRATE to an unreachable host, times out by @madolson (#3541)
  • Fix a potential crash from a dangling slot migration job reference when the migration client is reset by @murphyjacob4 (#3554)
  • Remove cached EVAL scripts when their scripting engine is unregistered, preventing dangling engine references by @eifrah-aws (#3503)
  • Fix a memory leak in GEOSEARCH BYPOLYGON when argument parsing fails, such as on an invalid COUNT by @bandalgomsu (#3568)
  • Fix a crash when a slot migration target node is removed from the cluster before the migration connects by @chenshi5012 (#3596)
  • Fix a crash when the module GetLRU/SetLRU/GetLFU/SetLFU APIs are called with a NULL key by @yaronsananes (#3610)
  • Fix an assertion failure in hash field expiration commands when a module blocks the client in a keyspace notification by @enjoy-binbin (#3743)
  • Fix a cluster UPDATE log message reading shard IDs past their fixed-length buffer by @enjoy-binbin (#3942)
  • Fix undefined behavior in the failover delay calculation when cluster-node-timeout is set below 30 milliseconds by @enjoy-binbin (#3941)
  • Reject zipmap RESTORE payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
  • Reject NAN scores in listpack- and ziplist-encoded sorted sets on RDB/RESTORE load, preventing a later crash on skiplist conversion by @madolson (#3921)
  • Fix a startup crash on 32-bit systems with 64-bit time_t, such as Alpine 3.23, caused by time value formatting mismatches by @chenshi5012 (#3787)
  • Fix corrupted client replies when IO threads are enabled, caused by a race between in-flight writes and reply buffer reuse by @nanyan0312 (#4060)
  • COMMAND INFO in RESP3 now returns the subcommands field as an Array instead of a Set for commands without subcommands by @rickrams (#3939)
  • The dual-channel replication RDB connection now announces the configured replica-announce-ip, avoiding stale replica entries behind NAT by @jdheyburn (#2846)
  • Prevent replicas from processing stale cluster packets and incorrectly promoting themselves to an empty primary within a shard by @zhijun42 (#2811)
  • Send the replica version on the dual-channel RDB connection so full syncs of data like hash field TTLs no longer fail by @hpatro (#4105)
  • Fix slot migration failure handling running twice on ownership changes and an out-of-order error reply in the internal SYNCSLOTS FINISH command by @chx9 (#3723)
  • Allow slot-migration-max-failover-repl-bytes to be set to -1 to disable the limit, as documented by @enjoy-binbin (#3443)
  • Fix CONFIG REWRITE producing negative values for memory configs such as maxmemory when set to very large values by @enjoy-binbin (#3440)
  • Reject SENTINEL SET values containing control characters and safely quote Sentinel config values to prevent config file injection by @eifrah-aws (#3847)
  • Reject control characters and delimiters in cluster AUX fields and validate cluster-announce-ip to prevent nodes.conf corruption or injection by @eifrah-aws (#3848)
  • Fix changes to lua-enable-insecure-api via CONFIG SET not taking effect when the option was set at startup by @enjoy-binbin (#4182)
  • Fix incorrect memory overhead reported for watched keys in client memory usage tracking by @enjoy-binbin (#3359)
  • Replica logs now report 'Connection reset by peer' instead of the misleading 'Success' when the primary closes the connection by @abmathur-ie (#3580)
  • Redact key names and user data from more log messages when hide-user-data-from-log is enabled by @zackcam (#3872)
  • Fix INFO replication reporting negative sync transfer sizes when the RDB exceeds 2GB during disk-based sync by @chx9 (#3811)
  • Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long installation paths by @pkhartsk (#3843)
  • valkey-cli --cluster del-node can now remove unreachable or failed nodes instead of failing with 'No such node ID' by @yang-z-o (#3209)
  • Fix valkey-cli crashing after --eval script execution on jemalloc/tcmalloc builds by @bandalgomsu (#3281)
  • valkey-cli --cluster fix now spreads uncovered slots randomly across primaries instead of assigning them all to one node by @abmathur-ie (#3586)

Full Changelog: https://github.com/valkey-io/valkey/compare/9.0.4...9.0.5

2026-07-22 06:35:07
valkey

9.1.1

Valkey 9.1.1 - Released Tue 21 July 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes

  • CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
  • CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)

Bug Fixes

  • Omit the implicit alldbs ACL rule from ACL LIST, ACL SAVE and CONFIG REWRITE so older versions can parse the output by @dvkashapov (#3964)
  • Improve throughput when IO threads are enabled by offloading object deallocation from the main thread by @roshkhatri (#3938)
  • Fix use-after-free crash when ACL LOAD removes a user whose authenticated client has its close deferred by @ranshid (#3800)
  • Enforce db= ACL permissions on every DB clause of COPY, closing a bypass with REPLACE or repeated DB tokens by @enjoy-binbin (#3801)
  • Enforce database-level ACLs for CLUSTER FLUSHSLOT, which removes keys from all databases by @enjoy-binbin (#3806)
  • Fix use-after-free in the module API when unregistering the first registered cluster message receiver by @eifrah-aws (#3846)
  • Fix HRANDFIELD with a positive count looping forever when non-expired fields are fewer than the requested count by @cjx-zar (#4047)
  • Fix clients left on the wrong database after module keyspace notifications for MOVE and COPY by @enjoy-binbin (#4024)
  • Fix Sentinel crash during coordinated failover when the command link to the old primary disconnects by @lukepalmer (#4068)
  • Fix crash when active hash field expiration leaves a single-entry expiry bucket whose last field is later removed by @ranshid (#3950)
  • Fix assertion in HEXPIRE, HGETDEL and HPERSIST when a module blocks the client in a keyspace notification callback by @enjoy-binbin (#3743)
  • Fix undefined behavior in the failover delay calculation when cluster-node-timeout is below 30 milliseconds by @enjoy-binbin (#3941)
  • Reject zipmap RESTORE/RDB payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
  • Reject NAN scores in listpack and ziplist encoded sorted sets on RDB/RESTORE load, preventing a crash on skiplist conversion by @madolson (#3921)
  • Fix corrupted replies (dropped leading bytes) caused by a reply buffer race when IO threads are enabled by @nanyan0312 (#4060)
  • Fix startup crash on 32-bit systems where time_t is 64-bit (such as Alpine 3.23) when generating INFO output by @chenshi5012 (#3787)
  • HGETDEL now returns a syntax error when the FIELDS keyword is missing or misplaced by @lcxn123 (#4049)
  • COMMAND INFO in RESP3 now returns the subcommands field as an array instead of a set for commands without subcommands by @rickrams (#3939)
  • Send the replica version on the dual-channel RDB connection so full syncs with newer encodings like hash field TTLs succeed by @hpatro (#4105)
  • Fix duplicate failure handling and an invalid reply sequence in cluster slot migration by @chx9 (#3723)
  • Reject control characters in SENTINEL SET values to prevent config-file injection via Sentinel config rewrite by @eifrah-aws (#3847)
  • Reject control characters and delimiters in cluster AUX fields and validate cluster-announce-ip to prevent nodes.conf injection by @eifrah-aws (#3848)
  • Redact key names and user data from more server log messages when hide-user-data-from-log is enabled by @zackcam (#3872)
  • ACL LOG now reports the denied database ID for COPY instead of the command name when db= access is denied by @enjoy-binbin (#3888)
  • Fix garbled shard IDs in the cluster UPDATE message log line by @enjoy-binbin (#3942)
  • Fix negative master_sync_total_bytes in INFO replication during disk-based sync when the RDB exceeds 2GB by @chx9 (#3811)
  • Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long paths by @pkhartsk (#3843)

Full Changelog: https://github.com/valkey-io/valkey/compare/9.1.0...9.1.1

2026-07-22 06:23:14
valkey

8.0.10

Valkey 8.0.10 - Released Tue 21 July 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes

  • CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to crash the server using CLIENT KILL (#4234)
  • CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers. Reported by @z0v3r1n and @lifip. (#4073)

Bug Fixes

  • Strictly validate CRLF line endings when parsing the RESP protocol, rejecting malformed requests as protocol errors by @enjoy-binbin (#2872)
  • Fix memory leak in ZDIFF/ZDIFFSTORE when the result set becomes empty before all input sets are processed by @sarthakaggarwal97 (#3342)
  • Fix crash caused by a race between asynchronous client freeing and IO threads reading from the closing client by @deepakrn (#3458)
  • Fix double free when loading corrupt stream RDB data containing duplicate consumer PEL entries by @enjoy-binbin (#3498)
  • Fix stream corruption and crash when XTRIM marks the last entry of a listpack node as deleted by @smkher (#3591)
  • Fix potential crash in TLS pending-data handling when the connection has no SSL object by @zuiderkwast (#3641)
  • Fix use-after-free when ACL LOAD removes a user whose authenticated client's free is deferred by @ranshid (#3800)
  • Fix use-after-free when a module unregisters the first-registered cluster message receiver for a message type by @eifrah-aws (#3846)
  • Fix crash when loading functions after FUNCTION FLUSH ASYNC and make FUNCTION FLUSH actually release Lua VM memory by @enjoy-binbin (#1826)
  • Fix file descriptor leak when a blocking connect times out, such as MIGRATE to an unreachable host by @madolson (#3541)
  • Fix crash in module LRU/LFU API functions (GetLRU, SetLRU, GetLFU, SetLFU) when passed a NULL key by @yaronsananes (#3610)
  • TLS synchronous I/O no longer leaves a blocking socket in non-blocking mode, preventing unexpected short reads by @xbasel (#1298)
  • Fix crash when CLUSTER SLOTS is called without a real client connection, such as from a module timer callback by @bandalgomsu (#2915)
  • Fix assertion crash in the IO thread job queue on ARM/aarch64 caused by memory store reordering by @jjuleslasarte (#3878)
  • Reject zipmap RESTORE payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
  • Reject NAN scores in listpack and ziplist encoded sorted sets on RDB load, preventing a later crash on skiplist conversion by @madolson (#3921)
  • Fix crash on 32-bit systems where time_t is 64-bit (e.g. Alpine with time64) when generating INFO output by @chenshi5012 (#3787)
  • COMMAND INFO in RESP3 now returns an empty Array instead of a Set for the subcommands field of commands without subcommands by @rickrams (#3939)
  • Manual failover votes are no longer restricted by two times the node timeout, preventing manual failover timeouts by @enjoy-binbin (#1305)
  • Automatic failover votes are no longer restricted by two times the node timeout, matching the manual failover change by @enjoy-binbin (#1356)
  • SENTINEL SET now rejects values containing control characters and config rewrite escapes them, preventing config injection by @eifrah-aws (#3847)
  • Reject control characters and delimiters in cluster AUX fields and cluster-announce-ip to prevent nodes.conf injection by @eifrah-aws (#3848)
  • Fix lua-enable-insecure-api yes not taking effect when set at startup via config file or command line by @enjoy-binbin (#3548)
  • Log 'Connection reset by peer' instead of the misleading 'Success' when the connection to the primary closes during sync by @abmathur-ie (#3580)
  • Redact key names and user data from additional server log messages when hide-user-data-from-log is enabled by @zackcam (#3872)
  • Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long paths by @pkhartsk (#3843)
  • valkey-cli --cluster del-node can now remove unreachable or failed nodes instead of failing with 'No such node ID' by @yang-z-o (#3209)
  • Fix valkey-cli --cluster assigning all uncovered slots to the same primary instead of distributing them randomly by @abmathur-ie (#3586)

Full Changelog: https://github.com/valkey-io/valkey/compare/8.0.9...8.0.10

2026-07-22 06:00:15
valkey

8.1.9

Valkey 8.1.9 - Released Tue 21 July 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes

  • CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
  • CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)

Bug Fixes

  • Fix clients being left on the wrong database after module keyspace notifications from commands like MOVE and COPY by @enjoy-binbin (#4024)
  • Fix an I/O thread job queue memory-ordering race that could trigger an assertion crash on ARM/aarch64 by @jjuleslasarte (#3878)
  • Reject zipmap RESTORE payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
  • Reject NAN scores when loading listpack/ziplist-encoded sorted sets, preventing a crash from crafted RESTORE payloads by @madolson (#3921)
  • Fix a startup crash when generating INFO output on 32-bit systems where time_t is 64-bit (e.g. Alpine time64) by @chenshi5012 (#3787)
  • Fix COMMAND INFO in RESP3 to reply with an empty Array instead of a Set for commands without subcommands by @rickrams (#3939)
  • Reject invalid characters in cluster AUX fields and cluster-announce-ip to prevent nodes.conf corruption and injection by @eifrah-aws (#3848)
  • Fix lua-enable-insecure-api having no effect when enabled at startup via config file or command line by @enjoy-binbin (#3548)
  • Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long installation paths by @pkhartsk (#3843)

Full Changelog: https://github.com/valkey-io/valkey/compare/8.1.8...8.1.9

2026-07-22 05:00:14
valkey

7.2.14

Valkey 7.2.14 - Released Tue 21 July 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes

  • CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
  • CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)

Bug Fixes

  • Strictly check CRLF when parsing requests and reject malformed input as a protocol error instead of misparsing it by @enjoy-binbin (#2872)
  • Fix a memory leak in ZDIFF and ZDIFFSTORE when the result set becomes empty during computation by @sarthakaggarwal97 (#3342)
  • Fix a double free when loading a stream consumer group from a corrupted RDB or RESTORE payload by @enjoy-binbin (#3498)
  • Fix a potential crash from a NULL pointer dereference when updating the TLS pending-data flag by @zuiderkwast (#3641)
  • Fix a Lua VM crash when loading functions after FUNCTION FLUSH ASYNC and ensure flushed scripts' memory is released by @enjoy-binbin (#1826)
  • Fix a use-after-free when a module unregisters and re-registers a cluster message receiver by @eifrah-aws (#3846)
  • Fix a file descriptor leak when a blocking connection attempt times out, e.g. during MIGRATE to an unreachable host by @madolson (#3541)
  • Fix a crash in the module API when VM_GetLRU, VM_SetLRU, VM_GetLFU, or VM_SetLFU is called with a NULL key by @yaronsananes (#3610)
  • Fix invalid memory access when loading a malformed zipmap payload via RESTORE (CVE-2026-25243) by @ranshid (#3619)
  • Reject zipmap payloads whose length fields overflow, which could cause out-of-bounds access on 32-bit platforms via RESTORE by @madolson (#3920)
  • Reject NAN scores in listpack and ziplist encoded sorted sets on RDB/RESTORE load, preventing a later server crash by @madolson (#3921)
  • Fix a startup crash when generating INFO output on 32-bit systems where time_t is 64-bit, such as Alpine 3.23 by @chenshi5012 (#3787)
  • Fix use of uninitialized memory when registering Lua functions with FUNCTION LOAD by @enjoy-binbin (#2750)
  • Fix listpack corruption and server crash when XTRIM marks the last entry in a stream listpack node as deleted by @smkher (#3591)
  • Fix COMMAND INFO returning the subcommands field as a RESP3 Set instead of an Array for commands without subcommands by @rickrams (#3939)
  • Reject control characters in SENTINEL SET values and escape them on config rewrite to prevent config-file injection by @eifrah-aws (#3847)
  • Reject control characters and unsafe delimiters in cluster AUX fields and cluster-announce-ip to prevent nodes.conf injection by @eifrah-aws (#3848)
  • Fix lua-enable-insecure-api having no effect when enabled at startup via the config file or command line by @enjoy-binbin (#3548)
  • Log the real error (e.g. Connection reset by peer) instead of the misleading Success on replication sync I/O errors by @abmathur-ie (#3580)
  • Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long paths by @pkhartsk (#3843)
  • Fix valkey-cli --cluster del-node failing with No such node ID when removing unreachable or failed nodes by @yang-z-o (#3209)
  • Fix valkey-cli --cluster fix assigning all uncovered slots to the same primary instead of spreading them randomly by @abmathur-ie (#3586)

Full Changelog: https://github.com/valkey-io/valkey/compare/7.2.13...7.2.14