VulnSea

redis vulnerabilities

CVEs whose affected-version data names the redis package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-92925High· 7.1
5d ago

A flaw was found in Redis community

A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacke…

TwilightRed Hat · pen-drive/pen-drive-scanner-rhel9EPSS 0.34%via NVD
CVE-2026-23479High· 8.8PoC
4mo ago

Redis is an in-memory data structure store

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is e…

Midnightredis · redisEPSS 1.4%via NVD
CVE-2026-25243High· 8.8PoC
4mo ago

Redis is an in-memory data structure store

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted seri…

Midnightredis · redisEPSS 3.7%via NVD
CVE-2026-23631High· 8.1PoC
4mo ago

Redis is an in-memory data structure store

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read…

Midnightredis · redisEPSS 2.8%via NVD
CVE-2020-21468High· 7.5
5y ago

A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS)

A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the vendor cannot reproduce this issue in a released version, such as 5.0.7.

Twilightredislabs · redisEPSS 1.2%via NVD
redis vulnerabilities (CVEs) · VulnSea