Catalog / Valkey

Valkey 7 to 8

Every Valkey 8.x release the archive holds, 23 of them, starting at 8.0.0 and running to 8.1.10. The publisher writes these one at a time and its documentation describes the version you are on, so the run between two majors is not laid out anywhere as a list.

Releases
23 23 carry notes
Opened
15 Sep 2024 2 years ago
Span
24 months to 31 Aug 2026
Breaking
1 tagged by the publisher

The turn

The last 7.x release the archive holds before the turn is 7.2.6, on 31 Jul 2024. 8.0.0 followed 46 days later. 7.x did not stop there. 8 more 7.x releases shipped after 8.0.0 opened, the last of them on 21 Jul 2026, so both lines were being maintained at once.

Tagged breaking

1 of these releases carries the breaking label: 8.0.2. The label is matched from words in the publisher’s own notes, so a release that changed an API without using the word does not carry it.

Every 8.x release

All Valkey releases
8.1.10securityaddedfixed

Valkey 8.1.10 - Released Mon 31 August 2026 Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Security Fixes GHSA-jcj7-v34w-v9vv: Fix a use-after-free in RDMA connection handling that

8.0.11securityfixeddeprecated

Valkey 8.0.11 - Released Mon 31 August 2026 Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Security Fixes GHSA-jcj7-v34w-v9vv: Fix a use-after-free in RDMA connection handling that

8.1.9securityfixed

Valkey 8.1.9 - Released Tue 21 July 2026 Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Security Fixes CVE-2026-56684: Fix a use-after-free in TLS connection handling that could al

8.0.10securityfixedremoved

Valkey 8.0.10 - Released Tue 21 July 2026 Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Security Fixes CVE-2026-56684: Fix a use-after-free in TLS connection handling that could a

8.1.8addedfixed

Upgrade urgency HIGH: There is a critical bug that may affect a subset of users. Bug fixes Fix ZDIFF algorithm 2 memory leak on early exit (#3342) Strictly check CRLF when parsing querybuf (#2872) Fix incorrect memory overhead calculation f

8.1.7securityfixed

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Security fixes (CVE-2026-23479) Use-After-Free in unblock client flow (CVE-2026-25243) Invalid Memory Access in RESTORE command (CVE-

8.0.9securityfixed

Upgrade urgency SECURITY: This release supersedes 8.0.8 (revoked) and includes security fixes we recommend you apply as soon as possible. Security fixes (CVE-2026-23479) Use-After-Free in unblock client flow (CVE-2026-25243) Invalid Memory

8.0.8

NOTICE: This release has been revoked. The 8.0.8 tag was placed on a commit that is not part of the 8.0 release branch. Users should upgrade to 8.0.9 instead.

8.1.6securityfixed

Valkey 8.1.6 Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Security fixes (CVE-2026-21863) Remote DoS with malformed Valkey Cluster bus message (CVE-2025-67733) RESP Protocol Inje

8.0.7securityfixedremoved

Valkey 8.0.7 Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Security fixes (CVE-2026-21863) Remote DoS with malformed Valkey Cluster bus message (CVE-2025-67733) RESP Protocol Inje

8.1.5fixed

Upgrade urgency MODERATE: Program an upgrade of the server, but it's not urgent. Bug fixes Fix Lua VM crash after FUNCTION FLUSH ASYNC + FUNCTION LOAD (#1826) Fix invalid memory address caused by hashtable shrinking during safe iteration (#

8.1.4securityfixed

Valkey 8.1.4 Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Security fixes (CVE-2025-49844) A Lua script may lead to remote code execution (CVE-2025-46817) A Lua script may lead to

8.0.6securityfixed

Valkey 8.0.6 Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Security fixes (CVE-2025-49844) A Lua script may lead to remote code execution (CVE-2025-46817) A Lua script may lead to

8.0.5securityaddedfixed

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Bug fixes Fix clients remaining blocked when reprocessing commands after certain blocking operations (#2109) Fix a memory corruption

8.1.3securityfixed

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Bug fixes Fix missing response when AUTH is errored inside a transaction (#2287) Security fixes CVE-2025-32023 prevent out-of-bounds

8.0.4securityfixed

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Security fixes CVE-2025-32023 prevent out-of-bounds write during hyperloglog operations (#2146) CVE-2025-48367 retry accept on transi

8.1.2securityaddedfixed

Upgrade urgency HIGH: This release includes CVE fix for valkey-check-aof tool, we recommend you apply as soon as possible if you use the tool. Security fixes CVE-2025-27151 Check length of AOF file name in valkey-check-aof (#2146) Bug fixes

8.1.1securityaddedfixed

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Security fixes (CVE-2025-21605) Limit output buffer for unauthenticated clients (#1994) Bug fixes Fix the build on less common platfo

8.0.3securityaddedfixed

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Security fixes (CVE-2025-21605) Limit output buffer for unauthenticated clients (#1993) Bug fixes Optimize RDB load performance and f

8.1.0securityaddedfixed

Valkey 8.1 release notes Upgrade urgency levels: LOW: No need to upgrade unless there are new features you want to use. MODERATE: Program an upgrade of the server, but it's not urgent. HIGH: There is a critical bug that may affect a subset

8.0.2breakingsecurityfixed

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Security fixes (CVE-2024-46981) Lua script commands may lead to remote code execution. (#1513) (CVE-2024-51741) Denial-of-service due

8.0.1securityfixed

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible. Bug fixes Fix a build issue with RDMA when using additional make parameters. (#1074) Fix an issue where CLUSTER SLOTS might return th

8.0.0fixedchanged

Upgrade urgency LOW: This is the first release of Valkey 8.0, which includes stability and performance improvements over the second release candidate. This release is fully compatible with Redis OSS 7.2.4. The 8.0.0 release also contains th