
Redis UAF RCE PoC collection for CVE-2026-23479: safe version checker, exploit module, GDB-assisted PoC, and Sigma detection rules for authorized testing.
HackSpeak distribution mirror. This repository consolidates three public PoC/detection tools, with code identical to each upstream.
⚠️ Contains actual exploit code and detection tools; for security research, vulnerability verification, and authorized testing only. Run in a disposable environment. Do not use against unauthorized systems.
CVE-2026-23479 is a Use-After-Free (UAF) vulnerability in Redis (redis-server) that can lead to Remote Code Execution (RCE).
unblockClientOnKey() (src/blocked.c) does not check the return value of processCommandAndResetClient() → after a blocked client is evicted, it continues to access a freed pointer → UAF;This repository contains three independent PoC/tools:
pduggusa-check/ — Safe Read-Only Version Detectorcd pduggusa-check
python3 check.py --host <Redis地址> --port 6379 [--password <密码>]
detection/ directory, for SIEM log detectionv1c0mmrt-scanner/ — Vulnerability Scannercd v1c0mmrt-scanner
pip install -r requirements.txt
python3 src/redis_cve_scanner.py
rizlmaulanaa-poc/ — GDB-Assisted PoCredisexp.py (exploit script)