Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.
History

Tue, 24 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-170
References
Metrics threat_severity

None

threat_severity

Important


Tue, 24 Feb 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Valkey-io
Valkey-io valkey
Vendors & Products Valkey-io
Valkey-io valkey

Mon, 23 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Description Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.
Title Valkey Affected by RESP Protocol Injection via Lua error_reply
Weaknesses CWE-74
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-02-23T19:39:29.136Z

Updated: 2026-02-23T19:39:29.136Z

Reserved: 2025-12-11T00:45:45.790Z

Link: CVE-2025-67733

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-23T20:28:53.280

Modified: 2026-02-23T20:28:53.280

Link: CVE-2025-67733

cve-icon Redhat

Severity : Important

Publid Date: 2026-02-23T19:39:29Z

Links: CVE-2025-67733 - Bugzilla