Try our Chrome extension
Easily add the current web-page from your browser directly into your changedetection.io tool, more great features coming soon!Changedetection.io needs your support!
You can help us by supporting changedetection.io on these platforms;
- Rate us at AlternativeTo.net
- Star us on GitHub
- Follow us at Twitter/X
- G2 Software reviews
- Check us out on LinkedIn
- And tell your friends and colleagues :)
The more popular changedetection.io is, the more time we can dedicate to adding amazing features!
Many thanks :)
changedetection.io team
Non ancora secondi fa
False
Non ancora secondi fa
Testo trigger Testo ignorato Testo bloccato
un'ora fa
Skip to content
Navigation Menu
Sign in Appearance settings
* Platform
+ AI CODE CREATION
o GitHub Copilot Write better code with AI
o GitHub Copilot app Direct agents from issue to merge
o MCP Registry Integrate external tools
+ DEVELOPER WORKFLOWS
o Actions Automate any workflow
o Codespaces Instant dev environments
o Issues Plan and track work
o Code Review Manage code changes
o Code Quality Enforce quality at merge
+ APPLICATION SECURITY
o GitHub Advanced Security Find and fix vulnerabilities
o Code security Secure your code as you build
o Secret protection Stop leaks before they start
+ EXPLORE
o Why GitHub
o Documentation
o Blog
o Changelog
o Marketplace
View all features
* Solutions
+ BY COMPANY SIZE
o Enterprises
o Small and medium teams
o Startups
o Nonprofits
+ BY USE CASE
o App Modernization
o DevSecOps
o DevOps
o CI/CD
o View all use cases
+ BY INDUSTRY
o Healthcare
o Financial services
o Manufacturing
o Government
o View all industries
View all solutions
* Resources
+ EXPLORE BY TOPIC
o AI
o Software Development
o DevOps
o Security
o View all topics
+ EXPLORE BY TYPE
o Customer stories
o Events & webinars
o Ebooks & reports
o Business insights
o GitHub Skills
+ SUPPORT & SERVICES
o Documentation
o Customer support
o Community forum
o Trust center
o Partners
View all resources
* Open Source
+ COMMUNITY
o GitHub Sponsors Fund open source developers
+ PROGRAMS
o Security Lab
o Maintainer Community
o Accelerator
o GitHub Stars
o Archive Program
+ REPOSITORIES
o Topics
o Trending
o Collections
* Enterprise
+ ENTERPRISE SOLUTIONS
o Enterprise platform AI-powered developer platform
+ AVAILABLE ADD-ONS
o GitHub Advanced Security Enterprise-grade security features
o Copilot for Business Enterprise-grade AI features
o Premium Support Enterprise-grade 24/7 support
* Pricing
Type / to search
Sign in
Sign up Appearance settings
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert
Uh oh!
There was an error while loading. Please reload this page.
valkey-io / valkey Public
* Notifications You must be signed in to change notification settings
* Fork 1.3k
* Star 26.9k
* Code
* Issues 556
* Pull requests 327
* Discussions
* Actions
* Projects
* Wiki
* Security and quality 10
* Insights
Additional navigation options
* Code
* Issues
* Pull requests
* Discussions
* Actions
* Projects
* Wiki
* Security and quality
* Insights
Releases: valkey-io/valkey
Releases Tags
Releases · valkey-io/valkey
Release list
* 9.1.1
* 9.0.5
* 8.1.9
* 8.0.10
* 7.2.14
* 8.1.8
* 9.1.0
* 9.0.4
* 8.1.7
* 8.0.9
Previous Next
Jump to release
* 9.1.1
* 9.0.5
* 8.1.9
* 8.0.10
* 7.2.14
* 8.1.8
* 9.1.0
* 9.0.4
* 8.1.7
* 8.0.9
Previous Next
9.1.1
9.1.1 Latest
Latest
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
sarthakaggarwal97 released this 21 Jul 23:41
9.1.1
d27f9ba
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
Valkey 9.1.1 - Released Tue 21 July 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security Fixes
* CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
* CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
* Omit the implicit alldbs ACL rule from ACL LIST, ACL SAVE and CONFIG REWRITE so older versions can parse the output by @dvkashapov (#3964)
* Improve throughput when IO threads are enabled by offloading object deallocation from the main thread by @roshkhatri (#3938)
* Fix use-after-free crash when ACL LOAD removes a user whose authenticated client has its close deferred by @ranshid (#3800)
* Enforce db= ACL permissions on every DB clause of COPY, closing a bypass with REPLACE or repeated DB tokens by @enjoy-binbin (#3801)
* Enforce database-level ACLs for CLUSTER FLUSHSLOT, which removes keys from all databases by @enjoy-binbin (#3806)
* Fix use-after-free in the module API when unregistering the first registered cluster message receiver by @eifrah-aws (#3846)
* Fix HRANDFIELD with a positive count looping forever when non-expired fields are fewer than the requested count by @cjx-zar (#4047)
* Fix clients left on the wrong database after module keyspace notifications for MOVE and COPY by @enjoy-binbin (#4024)
* Fix Sentinel crash during coordinated failover when the command link to the old primary disconnects by @lukepalmer (#4068)
* Fix crash when active hash field expiration leaves a single-entry expiry bucket whose last field is later removed by @ranshid (#3950)
* Fix assertion in HEXPIRE, HGETDEL and HPERSIST when a module blocks the client in a keyspace notification callback by @enjoy-binbin (#3743)
* Fix undefined behavior in the failover delay calculation when cluster-node-timeout is below 30 milliseconds by @enjoy-binbin (#3941)
* Reject zipmap RESTORE/RDB payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
* Reject NAN scores in listpack and ziplist encoded sorted sets on RDB/RESTORE load, preventing a crash on skiplist conversion by @madolson (#3921)
* Fix corrupted replies (dropped leading bytes) caused by a reply buffer race when IO threads are enabled by @nanyan0312 (#4060)
* Fix startup crash on 32-bit systems where time_t is 64-bit (such as Alpine 3.23) when generating INFO output by @chenshi5012 (#3787)
* HGETDEL now returns a syntax error when the FIELDS keyword is missing or misplaced by @lcxn123 (#4049)
* COMMAND INFO in RESP3 now returns the subcommands field as an array instead of a set for commands without subcommands by @rickrams (#3939)
* Send the replica version on the dual-channel RDB connection so full syncs with newer encodings like hash field TTLs succeed by @hpatro (#4105)
* Fix duplicate failure handling and an invalid reply sequence in cluster slot migration by @chx9 (#3723)
* Reject control characters in SENTINEL SET values to prevent config-file injection via Sentinel config rewrite by @eifrah-aws (#3847)
* Reject control characters and delimiters in cluster AUX fields and validate cluster-announce-ip to prevent nodes.conf injection by @eifrah-aws (#3848)
* Redact key names and user data from more server log messages when hide-user-data-from-log is enabled by @zackcam (#3872)
* ACL LOG now reports the denied database ID for COPY instead of the command name when db= access is denied by @enjoy-binbin (#3888)
* Fix garbled shard IDs in the cluster UPDATE message log line by @enjoy-binbin (#3942)
* Fix negative master_sync_total_bytes in INFO replication during disk-based sync when the RDB exceeds 2GB by @chx9 (#3811)
* Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long paths by @pkhartsk (#3843)
Full Changelog: 9.1.0...9.1.1
Contributors
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
lifip, lukepalmer, and 16 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 11 alexted, m3thom, uwu-420, raul-gherman, 3ldar, stevleibelt, omega8cc, Malacarne, Eyma88, YC-s-VEDA-Code, and kadireren7 reacted with thumbs up emoji 😄 4 alexted, Eyma88, YC-s-VEDA-Code, and kadireren7 reacted with laugh emoji 🎉 8 alexted, uwu-420, chriscroome, maciejcieslar, larouxn, Eyma88, YC-s-VEDA-Code, and kadireren7 reacted with hooray emoji ❤️ 11 caiohman, buriev, alexted, uwu-420, lightsigma96, phil-lipp, bandalgomsu, larouxn, Eyma88, YC-s-VEDA-Code, and kadireren7 reacted with heart emoji 🚀 6 alexted, uwu-420, GuillermoDLCO, larouxn, Eyma88, and YC-s-VEDA-Code reacted with rocket emoji 👀 3 alexted, Eyma88, and YC-s-VEDA-Code reacted with eyes emoji
All reactions
* 👍 11 reactions
* 😄 4 reactions
* 🎉 8 reactions
* ❤️ 11 reactions
* 🚀 6 reactions
* 👀 3 reactions
20 people reacted
9.0.5
9.0.5
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
sarthakaggarwal97 released this 21 Jul 23:40
9.0.5
a253513
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
Valkey 9.0.5 - Released Tue 21 July 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security Fixes
* CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
* CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
* Strictly validate CRLF terminators when parsing the RESP protocol; malformed requests now get a protocol error instead of being misparsed by @enjoy-binbin (#2872)
* Fix a use-after-free crash when creating slot import jobs during manual slot migrations by @twooster (#3283)
* Fix a memory leak in ZDIFF and ZDIFFSTORE when the result set becomes empty before all inputs are processed by @sarthakaggarwal97 (#3342)
* Fix HPERSIST sending a malformed reply that desynchronized the connection when used on a key of the wrong type by @madolson (#3516)
* Fix a crash from a race between IO threads and asynchronous client freeing by @deepakrn (#3458)
* Fix a double free when loading a stream with corrupt consumer PEL data from RDB or RESTORE by @enjoy-binbin (#3498)
* Fix listpack corruption and a subsequent crash when XTRIM marks the last entry of a stream listpack node as deleted by @smkher (#3591)
* Fix malformed replies when module callbacks build deferred-length arrays while a client's deferred reply buffer is active by @eifrah-aws (#3578)
* Fix a NULL pointer crash in TLS pending-data handling by @zuiderkwast (#3641)
* Fix a server crash when multiple RDMA clients disconnect at the same time by @quanyeyang (#3448)
* Fix a use-after-free when ACL LOAD deletes a user whose clients cannot be freed immediately by @ranshid (#3800)
* Fix a use-after-free when a module unregisters the first registered cluster message receiver for a message type by @eifrah-aws (#3846)
* Fix HRANDFIELD looping forever when a hash has fewer non-expired fields than the requested count by @cjx-zar (#4047)
* Fix clients being left on the wrong database after module keyspace notifications for commands like MOVE and COPY by @enjoy-binbin (#4024)
* Fix a Sentinel crash during coordinated failover when the connection to the old primary is disconnected by @lukepalmer (#4068)
* Fix underestimation of client output buffer memory when replies reference shared objects, so buffer limits are enforced correctly by @dvkashapov (#3306)
* Fix a crash on ARM/aarch64 caused by memory-ordering races in the IO thread job queue by @jjuleslasarte (#3878)
* Fix a crash when active hash field expiration leaves a single entry in a large expiration time-bucket by @ranshid (#3950)
* Fix a file descriptor leak when a blocking connection attempt, such as MIGRATE to an unreachable host, times out by @madolson (#3541)
* Fix a potential crash from a dangling slot migration job reference when the migration client is reset by @murphyjacob4 (#3554)
* Remove cached EVAL scripts when their scripting engine is unregistered, preventing dangling engine references by @eifrah-aws (#3503)
* Fix a memory leak in GEOSEARCH BYPOLYGON when argument parsing fails, such as on an invalid COUNT by @bandalgomsu (#3568)
* Fix a crash when a slot migration target node is removed from the cluster before the migration connects by @chenshi5012 (#3596)
* Fix a crash when the module GetLRU/SetLRU/GetLFU/SetLFU APIs are called with a NULL key by @yaronsananes (#3610)
* Fix an assertion failure in hash field expiration commands when a module blocks the client in a keyspace notification by @enjoy-binbin (#3743)
* Fix a cluster UPDATE log message reading shard IDs past their fixed-length buffer by @enjoy-binbin (#3942)
* Fix undefined behavior in the failover delay calculation when cluster-node-timeout is set below 30 milliseconds by @enjoy-binbin (#3941)
* Reject zipmap RESTORE payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
* Reject NAN scores in listpack- and ziplist-encoded sorted sets on RDB/RESTORE load, preventing a later crash on skiplist conversion by @madolson (#3921)
* Fix a startup crash on 32-bit systems with 64-bit time_t, such as Alpine 3.23, caused by time value formatting mismatches by @chenshi5012 (#3787)
* Fix corrupted client replies when IO threads are enabled, caused by a race between in-flight writes and reply buffer reuse by @nanyan0312 (#4060)
* COMMAND INFO in RESP3 now returns the subcommands field as an Array instead of a Set for commands without subcommands by @rickrams (#3939)
* The dual-channel replication RDB connection now announces the configured replica-announce-ip, avoiding stale replica entries behind NAT by @jdheyburn (#2846)
* Prevent replicas from processing stale cluster packets and incorrectly promoting themselves to an empty primary within a shard by @zhijun42 (#2811)
* Send the replica version on the dual-channel RDB connection so full syncs of data like hash field TTLs no longer fail by @hpatro (#4105)
* Fix slot migration failure handling running twice on ownership changes and an out-of-order error reply in the internal SYNCSLOTS FINISH command by @chx9 (#3723)
* Allow slot-migration-max-failover-repl-bytes to be set to -1 to disable the limit, as documented by @enjoy-binbin (#3443)
* Fix CONFIG REWRITE producing negative values for memory configs such as maxmemory when set to very large values by @enjoy-binbin (#3440)
* Reject SENTINEL SET values containing control characters and safely quote Sentinel config values to prevent config file injection by @eifrah-aws (#3847)
* Reject control characters and delimiters in cluster AUX fields and validate cluster-announce-ip to prevent nodes.conf corruption or injection by @eifrah-aws (#3848)
* Fix changes to lua-enable-insecure-api via CONFIG SET not taking effect when the option was set at startup by @enjoy-binbin (#4182)
* Fix incorrect memory overhead reported for watched keys in client memory usage tracking by @enjoy-binbin (#3359)
* Replica logs now report 'Connection reset by peer' instead of the misleading 'Success' when the primary closes the connection by @abmathur-ie (#3580)
* Redact key names and user data from more log messages when hide-user-data-from-log is enabled by @zackcam (#3872)
* Fix INFO replication reporting negative sync transfer sizes when the RDB exceeds 2GB during disk-based sync by @chx9 (#3811)
* Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long installation paths by @pkhartsk (#3843)
* valkey-cli --cluster del-node can now remove unreachable or failed nodes instead of failing with 'No such node ID' by @yang-z-o (#3209)
* Fix valkey-cli crashing after --eval script execution on jemalloc/tcmalloc builds by @bandalgomsu (#3281)
* valkey-cli --cluster fix now spreads uncovered slots randomly across primaries instead of assigning them all to one node by @abmathur-ie (#3586)
Full Changelog: 9.0.4...9.0.5
Contributors
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
twooster, zuiderkwast, and 28 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 3 m3thom, uwu-420, and YC-s-VEDA-Code reacted with thumbs up emoji 😄 1 YC-s-VEDA-Code reacted with laugh emoji 🎉 3 uwu-420, chriscroome, and YC-s-VEDA-Code reacted with hooray emoji ❤️ 3 uwu-420, bandalgomsu, and YC-s-VEDA-Code reacted with heart emoji 🚀 2 uwu-420 and YC-s-VEDA-Code reacted with rocket emoji 👀 1 YC-s-VEDA-Code reacted with eyes emoji
All reactions
* 👍 3 reactions
* 😄 1 reaction
* 🎉 3 reactions
* ❤️ 3 reactions
* 🚀 2 reactions
* 👀 1 reaction
5 people reacted
8.1.9
8.1.9
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
sarthakaggarwal97 released this 21 Jul 23:38
8.1.9
a9245aa
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
Valkey 8.1.9 - Released Tue 21 July 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security Fixes
* CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
* CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
* Fix clients being left on the wrong database after module keyspace notifications from commands like MOVE and COPY by @enjoy-binbin (#4024)
* Fix an I/O thread job queue memory-ordering race that could trigger an assertion crash on ARM/aarch64 by @jjuleslasarte (#3878)
* Reject zipmap RESTORE payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
* Reject NAN scores when loading listpack/ziplist-encoded sorted sets, preventing a crash from crafted RESTORE payloads by @madolson (#3921)
* Fix a startup crash when generating INFO output on 32-bit systems where time_t is 64-bit (e.g. Alpine time64) by @chenshi5012 (#3787)
* Fix COMMAND INFO in RESP3 to reply with an empty Array instead of a Set for commands without subcommands by @rickrams (#3939)
* Reject invalid characters in cluster AUX fields and cluster-announce-ip to prevent nodes.conf corruption and injection by @eifrah-aws (#3848)
* Fix lua-enable-insecure-api having no effect when enabled at startup via config file or command line by @enjoy-binbin (#3548)
* Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long installation paths by @pkhartsk (#3843)
Full Changelog: 8.1.8...8.1.9
Contributors
*
*
*
*
*
*
*
*
*
lifip, chenshi5012, and 7 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
8.0.10
8.0.10
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
sarthakaggarwal97 released this 21 Jul 23:37
8.0.10
23b3f6b
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
Valkey 8.0.10 - Released Tue 21 July 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security Fixes
* CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to crash the server using CLIENT KILL (#4234)
* CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
* Strictly validate CRLF line endings when parsing the RESP protocol, rejecting malformed requests as protocol errors by @enjoy-binbin (#2872)
* Fix memory leak in ZDIFF/ZDIFFSTORE when the result set becomes empty before all input sets are processed by @sarthakaggarwal97 (#3342)
* Fix crash caused by a race between asynchronous client freeing and IO threads reading from the closing client by @deepakrn (#3458)
* Fix double free when loading corrupt stream RDB data containing duplicate consumer PEL entries by @enjoy-binbin (#3498)
* Fix stream corruption and crash when XTRIM marks the last entry of a listpack node as deleted by @smkher (#3591)
* Fix potential crash in TLS pending-data handling when the connection has no SSL object by @zuiderkwast (#3641)
* Fix use-after-free when ACL LOAD removes a user whose authenticated client's free is deferred by @ranshid (#3800)
* Fix use-after-free when a module unregisters the first-registered cluster message receiver for a message type by @eifrah-aws (#3846)
* Fix crash when loading functions after FUNCTION FLUSH ASYNC and make FUNCTION FLUSH actually release Lua VM memory by @enjoy-binbin (#1826)
* Fix file descriptor leak when a blocking connect times out, such as MIGRATE to an unreachable host by @madolson (#3541)
* Fix crash in module LRU/LFU API functions (GetLRU, SetLRU, GetLFU, SetLFU) when passed a NULL key by @yaronsananes (#3610)
* TLS synchronous I/O no longer leaves a blocking socket in non-blocking mode, preventing unexpected short reads by @xbasel (#1298)
* Fix crash when CLUSTER SLOTS is called without a real client connection, such as from a module timer callback by @bandalgomsu (#2915)
* Fix assertion crash in the IO thread job queue on ARM/aarch64 caused by memory store reordering by @jjuleslasarte (#3878)
* Reject zipmap RESTORE payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
* Reject NAN scores in listpack and ziplist encoded sorted sets on RDB load, preventing a later crash on skiplist conversion by @madolson (#3921)
* Fix crash on 32-bit systems where time_t is 64-bit (e.g. Alpine with time64) when generating INFO output by @chenshi5012 (#3787)
* COMMAND INFO in RESP3 now returns an empty Array instead of a Set for the subcommands field of commands without subcommands by @rickrams (#3939)
* Manual failover votes are no longer restricted by two times the node timeout, preventing manual failover timeouts by @enjoy-binbin (#1305)
* Automatic failover votes are no longer restricted by two times the node timeout, matching the manual failover change by @enjoy-binbin (#1356)
* SENTINEL SET now rejects values containing control characters and config rewrite escapes them, preventing config injection by @eifrah-aws (#3847)
* Reject control characters and delimiters in cluster AUX fields and cluster-announce-ip to prevent nodes.conf injection by @eifrah-aws (#3848)
* Fix lua-enable-insecure-api yes not taking effect when set at startup via config file or command line by @enjoy-binbin (#3548)
* Log 'Connection reset by peer' instead of the misleading 'Success' when the connection to the primary closes during sync by @abmathur-ie (#3580)
* Redact key names and user data from additional server log messages when hide-user-data-from-log is enabled by @zackcam (#3872)
* Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long paths by @pkhartsk (#3843)
* valkey-cli --cluster del-node can now remove unreachable or failed nodes instead of failing with 'No such node ID' by @yang-z-o (#3209)
* Fix valkey-cli --cluster assigning all uncovered slots to the same primary instead of distributing them randomly by @abmathur-ie (#3586)
Full Changelog: 8.0.9...8.0.10
Contributors
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
zuiderkwast, smkher, and 18 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
7.2.14
7.2.14
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
sarthakaggarwal97 released this 21 Jul 21:35
7.2.14
499cfb9
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
Valkey 7.2.14 - Released Tue 21 July 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security Fixes
* CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
* CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
* Strictly check CRLF when parsing requests and reject malformed input as a protocol error instead of misparsing it by @enjoy-binbin (#2872)
* Fix a memory leak in ZDIFF and ZDIFFSTORE when the result set becomes empty during computation by @sarthakaggarwal97 (#3342)
* Fix a double free when loading a stream consumer group from a corrupted RDB or RESTORE payload by @enjoy-binbin (#3498)
* Fix a potential crash from a NULL pointer dereference when updating the TLS pending-data flag by @zuiderkwast (#3641)
* Fix a Lua VM crash when loading functions after FUNCTION FLUSH ASYNC and ensure flushed scripts' memory is released by @enjoy-binbin (#1826)
* Fix a use-after-free when a module unregisters and re-registers a cluster message receiver by @eifrah-aws (#3846)
* Fix a file descriptor leak when a blocking connection attempt times out, e.g. during MIGRATE to an unreachable host by @madolson (#3541)
* Fix a crash in the module API when VM_GetLRU, VM_SetLRU, VM_GetLFU, or VM_SetLFU is called with a NULL key by @yaronsananes (#3610)
* Fix invalid memory access when loading a malformed zipmap payload via RESTORE (CVE-2026-25243) by @ranshid (#3619)
* Reject zipmap payloads whose length fields overflow, which could cause out-of-bounds access on 32-bit platforms via RESTORE by @madolson (#3920)
* Reject NAN scores in listpack and ziplist encoded sorted sets on RDB/RESTORE load, preventing a later server crash by @madolson (#3921)
* Fix a startup crash when generating INFO output on 32-bit systems where time_t is 64-bit, such as Alpine 3.23 by @chenshi5012 (#3787)
* Fix use of uninitialized memory when registering Lua functions with FUNCTION LOAD by @enjoy-binbin (#2750)
* Fix listpack corruption and server crash when XTRIM marks the last entry in a stream listpack node as deleted by @smkher (#3591)
* Fix COMMAND INFO returning the subcommands field as a RESP3 Set instead of an Array for commands without subcommands by @rickrams (#3939)
* Reject control characters in SENTINEL SET values and escape them on config rewrite to prevent config-file injection by @eifrah-aws (#3847)
* Reject control characters and unsafe delimiters in cluster AUX fields and cluster-announce-ip to prevent nodes.conf injection by @eifrah-aws (#3848)
* Fix lua-enable-insecure-api having no effect when enabled at startup via the config file or command line by @enjoy-binbin (#3548)
* Log the real error (e.g. Connection reset by peer) instead of the misleading Success on replication sync I/O errors by @abmathur-ie (#3580)
* Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long paths by @pkhartsk (#3843)
* Fix valkey-cli --cluster del-node failing with No such node ID when removing unreachable or failed nodes by @yang-z-o (#3209)
* Fix valkey-cli --cluster fix assigning all uncovered slots to the same primary instead of spreading them randomly by @abmathur-ie (#3586)
Full Changelog: 7.2.13...7.2.14
Contributors
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
zuiderkwast, smkher, and 13 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 3 m3thom, uwu-420, and Eyma88 reacted with thumbs up emoji 🎉 4 uwu-420, chriscroome, maciejcieslar, and Eyma88 reacted with hooray emoji ❤️ 2 uwu-420 and Eyma88 reacted with heart emoji 🚀 2 uwu-420 and Eyma88 reacted with rocket emoji
All reactions
* 👍 3 reactions
* 🎉 4 reactions
* ❤️ 2 reactions
* 🚀 2 reactions
5 people reacted
8.1.8
8.1.8
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
zuiderkwast released this 02 Jun 18:12
8.1.8
9b4ab3b
Upgrade urgency HIGH: There is a critical bug that may affect a subset of users.
Bug fixes
* Fix ZDIFF algorithm 2 memory leak on early exit (#3342)
* Strictly check CRLF when parsing querybuf (#2872)
* Fix incorrect memory overhead calculation for watched keys (#3359)
* Fix valkey-cli --cluster del-node for unreachable nodes (#3209)
* Fix race condition during async client freeing with IO threading enabled (#3458)
* Fix double free in stream consumer PEL loading with corrupt RDB data (#3498)
* Fixes server crash when RDMA benchmark clients disconnect (#3448)
* Fix misleading log "I/O error reading bulk count from PRIMARY: Success" (#3580)
* Handle NULL pointer in streamTrim listpack delta calculation (#3591)
* Fix Deferred Reply Placeholders in Active Deferred Buffers (#3578)
* Add NULL check in updateSSLPendingFlag (#3641)
* Fix heap-use-after-free in ACL LOAD when client free is deferred (#3800)
* Redacting customer information when hide_user_data_from_log is true in rdb.c, networking.c, debug.c and t_hash (#3872)
* Fix use-after-free in VM_RegisterClusterMessageReceiver (#3846)
* Harden SENTINEL commands and config rewrite against control-character injection (#3847)
* Fix CLUSTER SLOTS crash when called from module timer callback (#2915)
Full Changelog: 8.1.7...8.1.8
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 7 uwu-420, phil-lipp, EmberCraze, dilansalindaL6, m3thom, Eyma88, and firengate reacted with thumbs up emoji 🎉 5 uwu-420, shogo82148, chriscroome, Eyma88, and firengate reacted with hooray emoji ❤️ 4 larouxn, uwu-420, Eyma88, and firengate reacted with heart emoji 🚀 4 uwu-420, 0xfeeddeadbeef, Eyma88, and firengate reacted with rocket emoji
All reactions
* 👍 7 reactions
* 🎉 5 reactions
* ❤️ 4 reactions
* 🚀 4 reactions
11 people reacted
9.1.0
9.1.0
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
lucasyonge released this 19 May 15:05
9.1.0
c9e8005
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
Upgrade urgency LOW: This is the first stable release of Valkey 9.1.
Security fixes
* (CVE-2026-23479) Use-After-Free in unblock client flow
* (CVE-2026-25243) Invalid Memory Access in RESTORE command
* (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution
New Features and enhanced behavior
* Add cluster bus network traffic usage metric in bytes by @hpatro (#3396)
* Reduce latency spikes during rehashing via incremental page release by @chzhoo (#3481)
Bug Fixes
* Fix(syncio): Set errno on EOF in syncRead and propagate to conn->last by @abmathur-ie (#3580)
* Fix GEOSEARCH BYPOLYGON leak on invalid COUNT by @bandalgomsu (#3568)
* Handle NULL pointer in streamTrim listpack delta calculation by @smkher (#3591)
* Fixes server crash when RDMA benchmark clients disconnect by @quanyeyang (#3448)
* Fix the memory leak in valkey-benchmark by @nmvk (#3643)
See also the release notes for 9.1.0-rc1 and 9.1.0-rc2.
Contributors
*
*
*
*
*
*
*
nmvk, smkher, and 5 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 19 m3thom, alexted, smkher, SpaceFarmer, omega8cc, uwu-420, Eyma88, YC-s-VEDA-Code, soundslocke, savonarola, and 9 more reacted with thumbs up emoji 😄 4 alexted, Eyma88, bandalgomsu, and edithturn reacted with laugh emoji 🎉 27 aosan, MatthiasHowellYopp, Morethanevil, yahorsi, martinrvisser, quanyeyang, huangzworks, chriscroome, dvkashapov, alexted, and 17 more reacted with hooray emoji ❤️ 11 alexted, smkher, uwu-420, Eyma88, YC-s-VEDA-Code, soundslocke, bandalgomsu, ivanbaldo, Jamim, firengate, and edithturn reacted with heart emoji 🚀 8 alexted, smkher, hoangphuocbk, uwu-420, Eyma88, soundslocke, ivanbaldo, and firengate reacted with rocket emoji 👀 4 alexted, Eyma88, ivanbaldo, and firengate reacted with eyes emoji
All reactions
* 👍 19 reactions
* 😄 4 reactions
* 🎉 27 reactions
* ❤️ 11 reactions
* 🚀 8 reactions
* 👀 4 reactions
36 people reacted
9.0.4
9.0.4
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
madolson released this 06 May 04:00
9.0.4
1cbee84
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
Upgrade urgency SECURITY: This release includes security fixes we recommend you
apply as soon as possible.
Security fixes
* (CVE-2026-23479) Use-After-Free in unblock client flow
* (CVE-2026-25243) Invalid Memory Access in RESTORE command
* (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 7 stevleibelt, shanezx-sc, arlanram, omega8cc, quanyeyang, ivanbaldo, and firengate reacted with thumbs up emoji 🎉 4 aosan, Mathis-6, koalalorenzo, and firengate reacted with hooray emoji
All reactions
* 👍 7 reactions
* 🎉 4 reactions
10 people reacted
8.1.7
8.1.7
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
madolson released this 06 May 04:00
8.1.7
65163a1
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
Upgrade urgency SECURITY: This release includes security fixes we recommend you
apply as soon as possible.
Security fixes
* (CVE-2026-23479) Use-After-Free in unblock client flow
* (CVE-2026-25243) Invalid Memory Access in RESTORE command
* (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
8.0.9
8.0.9
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
ranshid released this 06 May 16:19
8.0.9
479a022
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
Upgrade urgency SECURITY: This release supersedes 8.0.8 (revoked) and includes
security fixes we recommend you apply as soon as possible.
Security fixes
* (CVE-2026-23479) Use-After-Free in unblock client flow
* (CVE-2026-25243) Invalid Memory Access in RESTORE command
* (CVE-2026-23631) Use-after-free when full sync occurs during a yielding Lua/function execution
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 6 m3thom, uwu-420, stevleibelt, quanyeyang, kryoseu, and firengate reacted with thumbs up emoji 🎉 5 chriscroome, antstars, uwu-420, Mohamed-Fathy-Salah, and firengate reacted with hooray emoji ❤️ 3 uwu-420, caiohman, and firengate reacted with heart emoji 🚀 2 uwu-420 and firengate reacted with rocket emoji
All reactions
* 👍 6 reactions
* 🎉 5 reactions
* ❤️ 3 reactions
* 🚀 2 reactions
10 people reacted
Previous 1 2 3 4 5 Next
Previous Next
Footer
© 2026 GitHub, Inc.
Footer navigation
* Terms
* Privacy
* Security
* Status
* Community
* Docs
* Contact
* Manage cookies
* Do not share my personal information
You can’t perform that action at this time.
For now, Differences are performed on text, not graphically, only the latest screenshot is available.
Screenshot requires a Content Fetcher ( Sockpuppetbrowser, selenium, etc ) that supports screenshots.