Hi, The following vulnerability was published for important. CVE-2026-66373[0]: | Redis before 8.8.0, in the unusual case where an authenticated | attacker can execute RESTORE, allows remote code execution via a | RESTORE payload where the same NACK (pending entry) is referenced by | more than one consumer, because deleting both consumers via XGROUP | DELCONSUMER leads to a double free. NOTE: this issue exists because | of an incomplete fix for CVE-2026-25243. Fixed by: https://github.com/redis/redis/commit/4f62a8bf15c634187d8a87d874f8988032f90b6c (8.6.5) Fixed by: https://github.com/redis/redis/commit/04292292f2f5c180322292007a599a700611ebaf (7.2.15) fixed by: https://github.com/redis/redis/commit/41a958720e64e03576dd652d224aa46d22c096c3 (6.2.23) Issue exists because of an incomplete fix for CVE-2026-25243. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-66373 https://www.cve.org/CVERecord?id=CVE-2026-66373 Please adjust the affected versions in the BTS as needed.