Security scanners or automated defense tools report a vulnerability identified as CVE-2026-49980 against environments running VMware Tanzu for Valkey using Valkey Operator version 3.4.1.
VMware Tanzu for Valkey
A security vulnerability (CVE-2026-49980) has been identified within the version 3.4.1 operator.
A resolution is expected to be included in an upcoming release of the Valkey Operator.
Users are advised to monitor the official release notes for the announcement of the upcoming version.
https://techdocs.broadcom.com/us/en/vmware-tanzu/data-solutions/tanzu-for-valkey-on-kubernetes/3-4/valkey-on-kubernetes/release-notes.html