MEDIUM 6.0 NVD
CVE-2026-92925
In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding and total length but never checked that string-carrying extensions a
In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding
and total length but never checked that string-carrying extensions are
properly null-terminated, allowing a crafted packet to trigger
out-of-bounds reads when the payload is later consumed as a C string. This vulnerability can potentially lead to loss of confidentiality or remote denial of service. Redis Software / Redis Enterprise are not affected by this issue.
References
- https://github.com/redis/redis/commit/37894faeea11e2db28b9fc2af378a762d2c36523
- https://github.com/redis/redis/pull/15263
- https://github.com/redis/redis/releases/tag/8.10.0
This medium severity vulnerability with a CVSS score of 6.0 was published on 2026-09-17 via NVD.
vulnfeed aggregates 12865 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.