CVE Tools

Redis

78 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Redis, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Redis CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Redis CVEs per month
MonthCVEs
2024-103
2024-110
2024-120
2025-012
2025-020
2025-030
2025-041
2025-051
2025-060
2025-073
2025-080
2025-090
2025-104
2025-111
2025-120
2026-010
2026-020
2026-030
2026-040
2026-053
2026-060
2026-071
2026-081
2026-090

Severity

How the 78 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical79%
  • High4051%
  • Medium2329%
  • Low810%

Latest CVEs

The 15 most recently published vulnerabilities affecting Redis.

  1. CVE-2026-81934Redis TLS pending-data list use-after-free7.1
  2. CVE-2026-66373Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by ...7.5
  3. CVE-2026-25243redis-server RESTORE invalid memory access may allow remote code execution8.8
  4. CVE-2026-23631redis-server Lua use-after-free may allow remote code execution8.1
  5. CVE-2026-23479redis-server use-after-free in unblock client flow may allow remote code execution8.8
  6. CVE-2025-62507Redis: Bug in XACKDEL may lead to stack overflow and potential RCE8.8
  7. CVE-2025-49844Redis Lua Use-After-Free may lead to remote code execution9.9
  8. CVE-2025-46819Redis is vulnerable to DoS via specially crafted LUA scripts6.3
  9. CVE-2025-46818Redis: Authenticated users can execute LUA scripts as a different user6.0
  10. CVE-2025-46817Lua library commands may lead to integer overflow and potential RCE7.0
  11. CVE-2025-46686Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command argumen...3.5
  12. CVE-2025-48367Redis DoS Vulnerability due to bad connection error handling7.5
  13. CVE-2025-32023Redis allows out of bounds writes in hyperloglog commands leading to RCE7.0
  14. CVE-2025-27151redis-check-aof may lead to stack overflow and potential RCE4.7
  15. CVE-2025-21605Redis DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated client7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store