berabuddies/redis-poc: redis Authenticated RCE (stream NACK double free + TDigest heap overflow)
Non-destructive RCE exploits for Redis 6.2.22, 7.4.9, 8.6.4 via the stream consumer-group shared-NACK double free (CVE-2026-25589 incomplete fix family), and for Redis 8.8.0 via a newly found TDigest ...
Continue Reading