Skip to main content

Vendor/product archive

redis / redis CVEs

Beta · best-effort

46 CVEs tagged to redis / redis2 Critical, 23 High, 16 Medium, 5 Low, 0 Unrated.

CVE-2026-25243

Published May 5, 2026

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker wi…

CVSS 7.7 · High
evidence mentions
21
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2026-23631

Published May 5, 2026

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism…

CVSS 6.1 · Medium
evidence mentions
13
Buzz score
44.4
Vendor/product tagsBeta · best-effort

CVE-2026-23479

Published May 5, 2026

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` whe…

CVSS 7.7 · High
evidence mentions
13
Buzz score
44.4
Vendor/product tagsBeta · best-effort

CVE-2025-62507

Published Nov 4, 2025

Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's and trigger a stack buffer ov…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49844

Published Oct 3, 2025

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the gar…

CVSS 9.9 · Critical
evidence mentions
10
Buzz score
55.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-46819

Published Oct 3, 2025

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LUA script to read out-of-bound…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-46818

Published Oct 3, 2025

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate differe…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-46817

Published Oct 3, 2025

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause an integer o…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-48367

Published Jul 7, 2025

Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimatel…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32023

Published Jul 7, 2025

Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27151

Published May 29, 2025

Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51741

Published Jan 6, 2025

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46981

Published Jan 6, 2025

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the garbage collector and potentially…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31449

Published Oct 7, 2024

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit libra…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31228

Published Oct 7, 2024

Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service by using specially crafted, long string match patterns on su…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31227

Published Oct 7, 2024

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41056

Published Jan 10, 2024

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and pot…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41053

Published Sep 6, 2023

Redis is an in-memory database that persists on disk. Redis does not correctly identify keys accessed by `SORT_RO` and as a result may grant users executing this command access to…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-31294

Published Jul 15, 2023

Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24834

Published Jul 13, 2023

Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corr…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31655

Published May 18, 2023

redis v7.0.10 was discovered to contain a segmentation violation. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 46 CVEsPage 1 of 2