← Back to feed Search feed

Redis vulnerabilities

11 entries matching redis — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-66373Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code executioHIGH7.538%ileMicrosoft2026-07-14
CVE-2026-25243redis-server RESTORE invalid memory access may allow remote code executionUNKNOWN87%ileMicrosoft2026-05-12
CVE-2026-23631redis-server Lua use-after-free may allow remote code executionUNKNOWN85%ileMicrosoft2026-05-12
CVE-2026-23479redis-server use-after-free in unblock client flow may allow remote code executionUNKNOWN67%ileMicrosoft2026-05-12
CVE-2026-25588RedisTimeSeries RESTORE invalid memory access may allow remote code executionUNKNOWN62%ileMicrosoft2026-05-12
CVE-2026-25589RedisBloom RESTORE invalid memory access may allow remote code executionUNKNOWN69%ileMicrosoft2026-05-12
CVE-2025-48367Redis DoS Vulnerability due to bad connection error handlingHIGH7.551%ileMicrosoft2025-07-08
CVE-2025-32023Redis allows out of bounds writes in hyperloglog commands leading to RCEHIGH7.089%ileMicrosoft2025-07-08
CVE-2025-27151redis-check-aof may lead to stack overflow and potential RCEMEDIUM4.754%ileMicrosoft2025-05-13
CVE-2022-35977Integer overflow in certain command arguments can drive Redis to OOM panicMEDIUM5.598%ileMicrosoft2023-01-10
CVE-2023-22458Integer overflow in multiple Redis commands can lead to denial-of-serviceMEDIUM5.599%ileMicrosoft2023-01-10