Vulnerabilities in Redis
50 resultsVexday analysis
Redis apresenta um panorama de risco contido com apenas 3 CVEs registradas, nenhuma delas sob exploração ativa conhecida e sem severidade crítica. A vulnerabilidade mais recente foi publicada nos últimos 90 dias e envolve primariamente gestão inadequada de recursos (CWE-401), sugerindo risco moderado e sem indicadores de ameaça iminente.
CVE-2025-27151MEDIUMredis-check-aof may lead to stack overflow and potential RCEEPSS 0.8%CVE-2025-48367HIGHRedis DoS Vulnerability due to bad connection error handlingEPSS 0.7%CVE-2025-46818MEDIUMRedis: Authenticated users can execute LUA scripts as a different userEPSS 0.7%CVE-2025-29923LOWgo-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishmentEPSS 0.7%CVE-2026-66373HIGHRedis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE paylEPSS 0.5%CVE-2023-45145LOWRedis Unix-domain socket may have be exposed with the wrong permissions for a short time window.EPSS 0.4%CVE-2024-31227MEDIUMDenial-of-service due to malformed ACL selectors in RedisEPSS 0.4%CVE-2023-41053LOWRedis SORT_RO may bypass ACL configurationEPSS 0.3%CVE-2024-51741MEDIUMRedis allows denial-of-service due to malformed ACL selectorsEPSS 0.3%CVE-2025-46686LOWRedis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs beEPSS 0.3%