← Back to feed Search feed

Redis vulnerabilities

19 entries matching redis — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-93572## Summary `RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis rHIGH7.5NVD2026-09-18
CVE-2026-93435redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious HIGH8.738%ileNVD2026-09-17
CVE-2026-52727lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publicaHIGH7.226%ileNVD2026-09-17
CVE-2026-92925A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packetHIGH7.127%ileNVD2026-09-17
CVE-2026-92456yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerContrHIGH7.130%ileNVD2026-09-16
CVE-2026-91857Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affecMEDIUM5.37%ileNVD2026-09-15
CVE-2026-92002Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid exceMEDIUM5.132%ileNVD2026-09-15
CVE-2026-91842A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert oLOW1.230%ileNVD2026-09-15
CVE-2026-12944IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) CRITICAL9.616%ileNVD2026-09-14
CVE-2026-54246Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluMEDIUM5.727%ileNVD2026-09-14
CVE-2026-34501Apache Portable Runtime Utility: Heap buffer overflow in APR redis clientHIGH7.542%ileMicrosoft2026-08-11
CVE-2026-72568Redis - Heap Out-of-Bounds Read in Cluster Bus PING Message HandlerHIGH7.1Microsoft2026-08-11
CVE-2026-66373Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code executioHIGH7.545%ileMicrosoft2026-07-14
CVE-2026-23479redis-server use-after-free in unblock client flow may allow remote code executionUNKNOWN70%ileMicrosoft2026-05-12
CVE-2026-23631redis-server Lua use-after-free may allow remote code executionUNKNOWN86%ileMicrosoft2026-05-12
CVE-2026-25243redis-server RESTORE invalid memory access may allow remote code executionUNKNOWN89%ileMicrosoft2026-05-12
CVE-2026-25588RedisTimeSeries RESTORE invalid memory access may allow remote code executionUNKNOWN64%ileMicrosoft2026-05-12
CVE-2026-25589RedisBloom RESTORE invalid memory access may allow remote code executionUNKNOWN72%ileMicrosoft2026-05-12
CVE-2023-28856`HINCRBYFLOAT` can be used to crash a redis-server processMEDIUM6.568%ileMicrosoft2023-04-11