[Security] CVE-2024-46981: Lua GC manipulation leading to use-after-free
Author: vulgraphCreated Apr 11, 2026Updated Apr 14, 2026
Vulnerability
KeyDB inherits CVE-2024-46981 from Redis — Lua GC manipulation leading to use-after-free.
- CVE: CVE-2024-46981
- Severity: HIGH
Verification
The upstream fix for this CVE has not been cherry-picked into KeyDB. Verified by checking KeyDB latest master (git sha 603ebb27) — fix commit absent, vulnerable code path present.
Suggested Fix
Upstream Redis fix
Source: Snapchat/KeyDB