CVE-2026-72568
- EPSS 0.23%
- Veröffentlicht 10.08.2026 10:40:40
- Zuletzt bearbeitet 17.08.2026 14:20:22
Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
CVE-2026-66373
- EPSS 0.5%
- Veröffentlicht 25.07.2026 00:08:35
- Zuletzt bearbeitet 07.08.2026 00:16:38
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consume...
CVE-2026-25243
- EPSS 3.3%
- Veröffentlicht 05.05.2026 17:17:03
- Zuletzt bearbeitet 25.07.2026 11:10:00
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payloa...
CVE-2026-23631
- EPSS 2.81%
- Veröffentlicht 05.05.2026 17:17:03
- Zuletzt bearbeitet 25.07.2026 11:10:00
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disa...
CVE-2026-23479
- EPSS 1.29%
- Veröffentlicht 05.05.2026 17:17:02
- Zuletzt bearbeitet 25.07.2026 11:10:00
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during...
CVE-2025-62507
- EPSS 6.77%
- Veröffentlicht 04.11.2025 21:24:44
- Zuletzt bearbeitet 08.12.2025 16:23:27
Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's and trigger a stack buffer overflow, which may potentially lead to remote code execution. This issue...
CVE-2025-49844
- EPSS 86.77%
- Veröffentlicht 03.10.2025 19:27:23
- Zuletzt bearbeitet 20.03.2026 14:16:14
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote...
CVE-2025-46819
- EPSS 1.02%
- Veröffentlicht 03.10.2025 19:15:43
- Zuletzt bearbeitet 27.01.2026 19:37:47
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LUA script to read out-of-bound data or crash the server and subsequent denial of service. The problem ...
CVE-2025-46818
- EPSS 0.7%
- Veröffentlicht 03.10.2025 18:38:57
- Zuletzt bearbeitet 27.01.2026 19:38:03
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate different LUA objects and potentially run their own code in the context of ano...
CVE-2025-46817
- EPSS 3.69%
- Veröffentlicht 03.10.2025 17:52:48
- Zuletzt bearbeitet 27.01.2026 19:37:38
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause an integer overflow and potentially lead to remote code execution The problem exist...