redis vulnerabilities
CVEs whose affected-version data names the redis package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-92925High· 7.1A flaw was found in Redis community
A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacke…
CVE-2026-23479High· 8.8PoCRedis is an in-memory data structure store
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is e…
CVE-2026-25243High· 8.8PoCRedis is an in-memory data structure store
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted seri…
CVE-2026-23631High· 8.1PoCRedis is an in-memory data structure store
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read…
CVE-2020-21468High· 7.5A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS)
A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the vendor cannot reproduce this issue in a released version, such as 5.0.7.