Valkey published five security advisories in its first 21 months after the 2024 fork, then seven in the first eight months of 2026 along with almost three dozen security-adjacent fixes, a surge the maintainers attribute to cheap AI-assisted vulnerability hunting. They describe duplicate reports, including one two-week stretch where three researchers independently reported the same use-after-free in the script debugger, and note that a handful of maintainers must reproduce, triage, fix and coordinate embargoes for every report. Valkey is responding with AI-assisted adversarial testing and automated backporting while keeping human review, and quotes OpenStack, kernel, Red Hat and HAProxy maintainers seeing the same deluge.
Valkey says AI-driven bug reports are reshaping open source security work
Valkey published five security advisories in its first 21 months after the 2024 fork, then seven in the first eight months of 2026 along with almost three dozen security-adjacent fixes, a surge the maintainers attribute to cheap AI-assisted vulnerability hunting. They describe duplicate reports, including one two-week stretch where three researchers independently reported the same use-after-free in the script debugger, and note that a handful of maintainers must reproduce, triage, fix and coordinate embargoes for every report. Valkey is responding with AI-assisted adversarial testing and automated backporting while keeping human review, and quotes OpenStack, kernel, Red Hat and HAProxy maintainers seeing the same deluge.
Source: Valkey