19 entries matching redis — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-93572 | ## Summary `RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis r | HIGH | 7.5 | — | NVD | 2026-09-18 |
| CVE-2026-93435 | redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious | HIGH | 8.7 | 38%ile | NVD | 2026-09-17 |
| CVE-2026-52727 | lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publica | HIGH | 7.2 | 26%ile | NVD | 2026-09-17 |
| CVE-2026-92925 | A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packet | HIGH | 7.1 | 27%ile | NVD | 2026-09-17 |
| CVE-2026-92456 | yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerContr | HIGH | 7.1 | 30%ile | NVD | 2026-09-16 |
| CVE-2026-91857 | Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affec | MEDIUM | 5.3 | 7%ile | NVD | 2026-09-15 |
| CVE-2026-92002 | Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid exce | MEDIUM | 5.1 | 32%ile | NVD | 2026-09-15 |
| CVE-2026-91842 | A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert o | LOW | 1.2 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-12944 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) | CRITICAL | 9.6 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-54246 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves clu | MEDIUM | 5.7 | 27%ile | NVD | 2026-09-14 |
| CVE-2026-34501 | Apache Portable Runtime Utility: Heap buffer overflow in APR redis client | HIGH | 7.5 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-72568 | Redis - Heap Out-of-Bounds Read in Cluster Bus PING Message Handler | HIGH | 7.1 | — | Microsoft | 2026-08-11 |
| CVE-2026-66373 | Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code executio | HIGH | 7.5 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-23479 | redis-server use-after-free in unblock client flow may allow remote code execution | UNKNOWN | — | 70%ile | Microsoft | 2026-05-12 |
| CVE-2026-23631 | redis-server Lua use-after-free may allow remote code execution | UNKNOWN | — | 86%ile | Microsoft | 2026-05-12 |
| CVE-2026-25243 | redis-server RESTORE invalid memory access may allow remote code execution | UNKNOWN | — | 89%ile | Microsoft | 2026-05-12 |
| CVE-2026-25588 | RedisTimeSeries RESTORE invalid memory access may allow remote code execution | UNKNOWN | — | 64%ile | Microsoft | 2026-05-12 |
| CVE-2026-25589 | RedisBloom RESTORE invalid memory access may allow remote code execution | UNKNOWN | — | 72%ile | Microsoft | 2026-05-12 |
| CVE-2023-28856 | `HINCRBYFLOAT` can be used to crash a redis-server process | MEDIUM | 6.5 | 68%ile | Microsoft | 2023-04-11 |