| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Redis products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-41719 | A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. A... | 6.4 | 196 | Neutral | No |
| Yes |
| CVE-2026-25589 | RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE... | 8.8 | 646 | Neutral | Yes | Yes |
| CVE-2026-25588 | RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE comman... | 8.8 | 545 | Neutral | No | Yes |
| CVE-2026-25243 | Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to exec... | 8.8 | 646 | Low | Yes | Yes |
| CVE-2026-23631 | Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-afte... | 8.1 | 577 | Neutral | Yes | Yes |
| CVE-2026-23479 | Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a bloc... | 8.8 | 646 | Low | Yes | Yes |
| CVE-2025-62507 | Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's and trigger a stack buffer overflow, which may pot... | 8.8 | 646 | Neutral | Yes | Yes |
| CVE-2025-59271 | Redis Enterprise Elevation of Privilege Vulnerability | 8.7 | 587 | Neutral | No | Yes |
| CVE-2025-49844 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigg... | 9.9 | 687 | Viral | Yes | Yes |
| CVE-2025-48493 | The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the extension writes commands sequence to logs. Prior to version 2.0.20, AUTH par... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2025-48367 | Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of servic... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2025-46819 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LUA script to read out-of-bound data or crash the ser... | 7.1 | 407 | Neutral | Yes | Yes |
| CVE-2025-46818 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate different LUA objects and po... | 7.3 | 437 | Neutral | Yes | Yes |
| CVE-2025-46817 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause an integer overflow and potential... | 8.8 | 646 | Neutral | Yes | Yes |
| CVE-2025-32023 | Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a stack/heap... | 7.8 | 533 | Low | Yes | Yes |
| CVE-2025-27151 | Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy wit... | 9.8 | 588 | Neutral | No | Yes |
| CVE-2025-21605 | Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An unauthenticated client can cause unlimited growth of output buffers, until the ser... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2024-51741 | Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and sub... | 4.4 | 90 | Neutral | No | Yes |
| CVE-2024-46981 | Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the garbage collector and potentially lead to remote code ... | 9.8 | 690 | Neutral | Yes | Yes |
| CVE-2024-43590 | Visual C++ Redistributable Installer Elevation of Privilege Vulnerability | 7.8 | 474 | Neutral | No | Yes |