Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

redis — Vulnerabilities & Security Advisories 58

All 58 CVE vulnerabilities found in redis, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for the product Redis, focusing on specific weakness types and associated tags. It collects known security flaws reported in public databases, covering the timeframe from the product's initial release through the most recent advisory. Here you can track vendor-issued security advisories, understand the prevalence of a particular weakness class, and review the complete vulnerability history for this product.

Vendor: redis

CVE ID Title CVSS Severity Published
CVE-2026-81934 Redis TLS pending-data list use-after-free CWE-416 7.1 High 2026-08-27
CVE-2026-66373 Redis 资源管理错误漏洞 CWE-415 7.5 High 2026-07-25
CVE-2026-25243 redis-server RESTORE invalid memory access may allow remote code execution CWE-122 8.8 - 2026-05-05
CVE-2026-23631 redis-server Lua use-after-free may allow remote code execution CWE-416 8.8 - 2026-05-05
CVE-2026-23479 redis-server use-after-free in unblock client flow may allow remote code execution CWE-416 8.8 - 2026-05-05
CVE-2025-62507 Redis: Bug in XACKDEL may lead to stack overflow and potential RCE CWE-20 8.8AI High AI 2025-11-04
CVE-2025-49844 Redis Lua Use-After-Free may lead to remote code execution CWE-416 10.0 Critical 2025-10-03
CVE-2025-46819 Redis is vulnerable to DoS via specially crafted LUA scripts CWE-190 6.3 Medium 2025-10-03
CVE-2025-46818 Redis: Authenticated users can execute LUA scripts as a different user CWE-94 6.0 Medium 2025-10-03
CVE-2025-46817 Lua library commands may lead to integer overflow and potential RCE CWE-190 7.0 High 2025-10-03
CVE-2025-46686 Redis 安全漏洞 CWE-401 3.5 Low 2025-07-23
CVE-2025-48367 Redis DoS Vulnerability due to bad connection error handling CWE-770 7.5 High 2025-07-07
CVE-2025-32023 Redis allows out of bounds writes in hyperloglog commands leading to RCE CWE-680 7.0 High 2025-07-07
CVE-2025-27151 redis-check-aof may lead to stack overflow and potential RCE CWE-20 4.7 Medium 2025-05-29
CVE-2025-21605 Redis DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated client CWE-770 7.5 High 2025-04-23
CVE-2024-51741 Redis allows denial-of-service due to malformed ACL selectors CWE-20 4.4 Medium 2025-01-06
CVE-2024-46981 Redis' Lua library commands may lead to remote code execution CWE-416 7.0 High 2025-01-06
CVE-2024-31449 Lua library commands may lead to stack overflow and RCE in Redis CWE-20 7.0 High 2024-10-07
CVE-2024-31228 Denial-of-service due to unbounded pattern matching in Redis CWE-674 5.5 Medium 2024-10-07
CVE-2024-31227 Denial-of-service due to malformed ACL selectors in Redis CWE-20 4.4 Medium 2024-10-07
CVE-2023-41056 Redis vulnerable to integer overflow in certain payloads CWE-762 8.1 High 2024-01-10
CVE-2023-45145 Redis Unix-domain socket may have be exposed with the wrong permissions for a short time window. CWE-668 3.6 Low 2023-10-18
CVE-2023-41053 Redis SORT_RO may bypass ACL configuration CWE-269 3.3 Low 2023-09-06
CVE-2022-24834 Heap overflow issue with the Lua cjson library used by Redis CWE-122 7.0 High 2023-07-13
CVE-2023-36824 Heap overflow in COMMAND GETKEYS and ACL evaluation in Redis CWE-122 7.4 High 2023-07-11
CVE-2023-28856 `HINCRBYFLOAT` can be used to crash a redis-server process CWE-617 5.5 Medium 2023-04-18
CVE-2023-28425 Specially crafted MSETNX command can lead to denial-of-service CWE-77 5.5 Medium 2023-03-20
CVE-2023-25155 Integer Overflow in several Redis commands can lead to denial of service. CWE-190 5.5 Medium 2023-03-02
CVE-2022-36021 Redis string pattern matching can be abused to achieve Denial of Service CWE-407 5.5 Medium 2023-03-01
CVE-2022-35977 Integer overflow in certain command arguments can drive Redis to OOM panic CWE-190 5.5 Medium 2023-01-20

All 58 known CVE vulnerabilities affecting redis with full Chinese analysis, references, and POCs where available.