- Fixed multiple heap OOB write and use‑after‑free vulnerabilities in CMSketch loading, TopK cleanup, and TLS pending data handling.
- Patched ACL permission bypasses in SORT, GEORADIUS*, and XREAD* commands, and corrected TLS client certificate authentication bypass via truncated Common Names.
- Resolved memory corruption and potential remote code execution vectors in RDB loading, vector set handling, and blocked client list processing.