VYPR

Redis

by Redis

Source repositories

CVEs (75)

  • CVE-2022-31144HigJul 19, 2022
    risk 0.46cvss 7.0epss 0.03

    Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is…

  • CVE-2026-66373HigJul 25, 2026
    risk 0.42cvss 7.5epss 0.01

    Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER…

  • CVE-2025-21605HigApr 23, 2025
    risk 0.42cvss 7.5epss 0.01

    Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An unauthenticated client can cause unlimited growth of output buffers, until the server runs out of memory or is killed. By default, the Redis configuration does…

  • CVE-2019-10193HigJul 11, 2019
    risk 0.42cvss 7.2epss 0.24

    A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of…

  • CVE-2022-3734MedOct 28, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll. The manipulation leads to uncontrolled search path. The attack can be initiated remotely. The…

  • CVE-2016-10517HigOct 24, 2017
    risk 0.41cvss 7.4epss 0.02

    networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

  • CVE-2026-92925HigSep 17, 2026
    risk 0.39cvss 7.1epss 0.00

    A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to…

  • CVE-2024-46981HigJan 6, 2025
    risk 0.39cvss 7.0epss 0.08

    Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the garbage collector and potentially lead to remote code execution. The problem is fixed in 7.4.2, 7.2.7, and 6.2.17. An additional…

  • CVE-2021-3470MedMar 31, 2021
    risk 0.35cvss 5.3epss 0.01

    A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc, leading to potential out of bound write or process crash. Effectively this flaw does not affect the vast majority…

  • CVE-2024-51741MedJan 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

  • CVE-2013-0180MedNov 1, 2019
    risk 0.29cvss 5.5epss 0.00

    Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.

  • CVE-2013-0178MedNov 1, 2019
    risk 0.29cvss 5.5epss 0.00

    Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.

  • CVE-2016-2121MedOct 31, 2018
    risk 0.26cvss 4.0epss 0.00

    A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive information. A local, unprivileged user could possibly use this flaw to access unauthorized system information.

  • CVE-2025-46686LowJul 23, 2025
    risk 0.23cvss 3.5epss 0.00

    Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient…

  • CVE-2013-7458LowAug 10, 2016
    risk 0.14cvss 3.3epss 0.00

    linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.

  • CVE-2018-11218CriJun 17, 2018
    risk 0.08cvss 9.8epss 0.74

    Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.

  • CVE-2025-49844CriOct 3, 2025
    risk 0.07cvss 9.9epss 0.82

    Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem…

  • CVE-2023-22458MedJan 20, 2023
    risk 0.06cvss 5.5epss 0.72

    Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or…

  • CVE-2022-36021MedMar 1, 2023
    risk 0.05cvss 5.5epss 0.60

    Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang and consume 100% CPU time. The problem is fixed…

  • CVE-2018-12453HigJun 16, 2018
    risk 0.05cvss 7.5epss 0.18

    Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a stream.