Impact
A weakness in valkey-io's Valkey database up to versions 9.0.5 and 9.1.1 allows an attacker to manipulate the didx argument of the kvstoreGetHashtable function, resulting in an out‑of‑bounds read that can cause a denial‑of‑service during the server boot process if a crafted RDB file is loaded.
Affected Systems
The affected product is valkey-io's Valkey database. Versions up to and including 9.0.5 and 9.1.1 are impacted.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity. Exploitation requires cluster mode and an attacker‑controlled dump.rdb file present at startup, so the conditions are highly specific and do not permit a remote unauthenticated network attack before boot. The EPSS score is not available and the vulnerability is not listed in KEV, suggesting limited public exploitation activity. Nevertheless, because the flaw can halt service availability, it merits timely attention, especially in environments that use cluster mode.
OpenCVE Enrichment