- Fixed multiple heap and out‑of‑bounds write vulnerabilities (CVE‑2026‑62356) including CMSketch RDB loading and TopK cleanup
- Patched use‑after‑free bugs in TLS pending‑data list and blocked client handling, and corrected ACL permission bypasses in SORT/GEORADIUS/XREAD commands
- Resolved vector‑set memory corruption issues and a malicious RDB payload that could lead to remote code execution