CRITICAL9.8CVE-2025-27151redis-check-aof may lead to stack overflow and potential RCE >= 7.0.0, < 7.0.15-r4
CRITICAL9.8CVE-2024-46981Redis' Lua library commands may lead to remote code execution >= 6.2.0, < 6.2.18-r0
CRITICAL9.8CVE-2022-35951Redis subject to Integer Overflow leading to Remote Code Execution via Heap Overflow >= 7.0.0, < 7.0.5-r0
CRITICAL9.8An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x befo…
>= 4.0, < 3.2.12-r0
CRITICAL9.8redis - security update
>= 4.0, < 3.2.12-r0
HIGH8.8Lua library commands may lead to stack overflow and RCE in Redis
>= 2.8.18, < 6.2.18-r0
HIGH8.8Heap overflow issue with the Lua cjson library used by Redis
>= 2.6.0, < 7.0.12-r0
HIGH8.8Heap overflow in COMMAND GETKEYS and ACL evaluation in Redis
>= 7.0.0, < 7.0.12-r0
HIGH8.8Potential heap overflow in Redis
>= 7.0, < 7.0.4-r0
HIGH8.8Integer overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platforms
>= 5.0.0, < 5.0.14-r0
HIGH8.8Lua scripts can overflow the heap-based Lua stack in Redis
>= 2.6, < 5.0.14-r0
HIGH8.8Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker.
>= 6.0.0, < 6.0.14-r0
HIGH8.8Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker.
>= 6.0.0, < 6.0.13-r0
HIGH8.8redis - security update
>= 4.0, < 5.0.11-r0
HIGH8.1Redis vulnerable to integer overflow in certain payloads
>= 7.0.9, < 7.0.15-r0
HIGH7.8Lua scripts can be manipulated to overcome ACL rules in Redis
from 0, < 6.2.7-r0
HIGH7.7redis - security update
>= 6.0.0, < 6.0.3-r0
HIGH7.5Redis DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated client
>= 2.6.0, < 6.2.18-r0
HIGH7.5Integer overflow issue with strings in Redis
>= 5.0.0, < 5.0.14-r0
HIGH7.5Integer overflow issue with intsets in Redis
>= 5.0.0, < 5.0.14-r0
HIGH7.5DoS vulnerability in Redis
>= 5.0.0, < 5.0.14-r0
HIGH7.5Vulnerability in handling large ziplists
>= 5.0.0, < 5.0.14-r0
HIGH7.5Integer overflow issue with Streams in Redis
>= 5.0.0, < 5.0.14-r0
HIGH7.5redis - regression update
>= 2.2.0, < 5.0.13-r0
HIGH7.5redis - security update
>= 2.8.0, < 5.0.5-r1
HIGH7.2A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5…
>= 3.0.0, < 5.0.4-r0
HIGH7.2redis - security update
>= 3.0.0, < 5.0.4-r0
MEDIUM6.5Denial-of-service due to unbounded pattern matching in Redis
>= 2.2.5, < 6.2.18-r0
MEDIUM5.5Integer overflow in multiple Redis commands can lead to denial-of-service
>= 6.2.0, < 6.2.9-r0
MEDIUM5.5Integer overflow in certain command arguments can drive Redis to OOM panic
>= 6.0.0, < 6.2.9-r0
MEDIUM5.5A Malformed Lua script can crash Redis
from 0, < 6.2.7-r0
MEDIUM5.3A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than je…
>= 6.0.0, < 5.0.11-r0
MEDIUM4.4Redis allows denial-of-service due to malformed ACL selectors
>= 7.0.0, < 7.0.15-r2
MEDIUM4.4Denial-of-service due to malformed ACL selectors in Redis
>= 7.0.0, < 7.0.15-r1
MEDIUM4.3Vulnerability in Lua Debugger in Redis
>= 3.2.0, < 5.0.14-r0
LOW3.6Redis Unix-domain socket may have be exposed with the wrong permissions for a short time window.
>= 2.6.0, < 6.2.14-r0
LOW3.3Redis SORT_RO may bypass ACL configuration
>= 7.0, < 7.0.13-r0
LOW3.3Redis Crash Report debug.c sigsegvHandler denial of service
>= 7.0.0, < 7.0.7-r0