VYPR

rpm package

opensuse/redis-modules&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/redis-modules&distro=openSUSE%20Leap%2016.0

Vulnerabilities (5)

  • CVE-2026-25589HigMay 5, 2026
    affected < 8.10.1-bp160.1.1fixed 8.10.1-bp160.1.1

    RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a serv

  • CVE-2026-25588HigMay 5, 2026
    affected < 8.10.1-bp160.1.1fixed 8.10.1-bp160.1.1

    RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with

  • CVE-2026-25243HigMay 5, 2026
    affected < 8.10.1-bp160.1.1fixed 8.10.1-bp160.1.1

    Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory

  • CVE-2026-23631HigMay 5, 2026
    affected < 8.10.1-bp160.1.1fixed 8.10.1-bp160.1.1

    Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which

  • CVE-2026-23479HigMay 5, 2026
    affected < 8.10.1-bp160.1.1fixed 8.10.1-bp160.1.1

    Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated a