On this page
What the register shows
22 CVEs in twenty-one months: 14 in redis-server itself, 3 in the RedisBloom and RedisTimeSeries modules that ship inside Redis 8, and 5 that Valkey disclosed for its own code. One is Critical: CVE-2025-49844, the Lua use-after-free that Wiz Research named RediShell, scored 9.9 by Redis and present in every version with Lua scripting. 15 are High and 6 Medium. Almost all of them need an authenticated connection, but four can be triggered without authentication, and most of the High rows are memory-safety bugs reachable through ordinary commands such as EVAL, RESTORE or the HyperLogLog family.
The release-series view matters more than the count. Redis 6.2, 7.2 and 7.4 received every fix that applied to them. Redis 7.0 received none: it is affected by 12 of the 14 redis-server CVEs here, and its last release, 7.0.15, predates all of them. Redis 8.0 is still listed as supported until 1 December 2026, yet no 8.0.x release has shipped since February 2026, so 6 CVEs published since May 2026 are unfixed on that line. Valkey patched every supported series, 7.2 through 9.1, for every CVE that affected it.
Severity distribution
Severity is the rating published in each GitHub security advisory, which is the CNA record for these projects. NVD sometimes scores the same CVE higher; CVE-2024-46981, for example, is 7.0 High in the Redis advisory and 9.8 Critical in NVD's own analysis. Where the ratings differ this register keeps the advisory's, as the RabbitMQ register does. The same bug can also be rated differently by each project: Valkey rates CVE-2025-49844 High (8.8) where Redis rates it Critical (9.9).
| Severity | CVEs | Share |
|---|---|---|
| Critical | 1 | 5% |
| High | 15 | 68% |
| Medium | 6 | 27% |
| Low | 0 | 0% |
CVEs by year and source
Disclosure has been steady rather than bursty: 11 in 2025 and 11 so far in 2026. The 2026 rows come in batches. Redis published three redis-server CVEs and two module CVEs together on 5 May 2026, several of them found during the Wiz Zeroday Cloud event, and Valkey released fixes for the same three redis-server bugs the following day. Lua scripting is the single largest source: six of the 14 redis-server CVEs are in the Lua engine or reachable only through scripts.
| Year | redis-server | Redis 8 modules | Valkey only | Total |
|---|---|---|---|---|
| 2025 | 11 | 0 | 0 | 11 |
| 2026 | 3 | 3 | 5 | 11 |
Redis: exposure by release series
Each row counts the CVEs in this register that affected a release of that series, and how many of them a later release in the same series fixed. A series that shipped after a fix landed, such as 8.4 for the 2025 Lua bugs, is not counted as affected. Redis 6.2 has had every applicable fix backported, most recently 6.2.24 in August 2026, and remains supported until 1 April 2027. Redis 7.0 left support in 2024 and shows 12 affected and none fixed. Redis 8.0 shows 6 unfixed: three redis-server CVEs from May 2026 and three module CVEs, all fixed on 8.2 and later. The latest-release column is the version to run, not merely the first fix.
| Series | Community end of life | Latest release (9 Oct 2026) | CVEs affecting the series | Fixed in the series | No fix in the series |
|---|---|---|---|---|---|
| Redis 6.2 | 1 April 2027 | 6.2.24 | 9 | 9 | 0 |
| Redis 7.0 | Past end of life; not on Redis's supported list | 7.0.15 | 12 | 0 | 12 |
| Redis 7.2 | 1 December 2029 | 7.2.16 | 13 | 13 | 0 |
| Redis 7.4 | 1 December 2029 | 7.4.11 | 13 | 13 | 0 |
| Redis 8.0 | 1 December 2026 | 8.0.6 | 13 | 7 | 6 |
| Redis 8.2 | 1 September 2030 | 8.2.10 | 11 | 11 | 0 |
| Redis 8.4 | Not yet set | 8.4.7 | 6 | 6 | 0 |
| Redis 8.6 | Not yet set | 8.6.7 | 6 | 6 | 0 |
| Redis 8.8 | Not yet set | 8.8.3 | 1 | 1 | 0 |
| Redis 8.10 | Not yet set | 8.10.2 | 1 | 1 | 0 |
Valkey: exposure by release series
Valkey's policy is three years of maintenance from each minor release's first release, and five years of security support for the last minor of each major. Every series below is inside that window, and every CVE that affected a series has a fixed release on it. Valkey 7.2 and 8.0 carry the most CVEs because they predate most fixes; 9.1 shipped with the May 2026 fixes already in it. Note that Valkey 8.0.8 was revoked because its tag was placed on the wrong commit; use 8.0.9 or later.
| Series | Maintenance support ends | Security support ends | Latest release (9 Oct 2026) | CVEs fixed in the series |
|---|---|---|---|---|
| Valkey 7.2 | 16 April 2027 | 16 April 2029 | 7.2.14 | 17 |
| Valkey 8.0 | 15 September 2027 | 15 September 2027 | 8.0.11 | 17 |
| Valkey 8.1 | 31 March 2028 | 31 March 2030 | 8.1.10 | 15 |
| Valkey 9.0 | 21 October 2028 | 21 October 2028 | 9.0.6 | 8 |
| Valkey 9.1 | 19 May 2029 | 19 May 2031 | 9.1.2 | 2 |
The complete register, most recent first
Affected ranges and fixed releases are quoted from the project advisories and release notes. A fixed release is the floor, not the target: later releases in the same series include every earlier fix. "No fix" means the series was affected and no release on it contains the fix. Redis 8 modules apply to Redis 8.0 and later, where the probabilistic and time series types ship in the core distribution, and to Redis Stack builds that load the module.
| CVE | Published | Severity (CVSS) | Component | Summary | Affected | Fixed in Redis | Fixed in Valkey |
|---|---|---|---|---|---|---|---|
| CVE-2026-25243 | 2026-05-05 | High (7.7, CVSS 4.0) | redis-server | Invalid memory access in RESTORE with a crafted payload; may lead to remote code execution | All versions | 6.2.22, 7.0.x: no fix, 7.2.14, 7.4.9, 8.0.x: no fix, 8.2.6, 8.4.3, 8.6.3 | 7.2.13, 8.0.9, 8.1.7, 9.0.4 |
| CVE-2026-23631 | 2026-05-05 | Medium (6.1, CVSS 4.0) | redis-server | Lua use-after-free during replica full sync on replicas with replica-read-only disabled; may lead to remote code execution | 7.0 and later | 7.0.x: no fix, 7.2.14, 7.4.9, 8.0.x: no fix, 8.2.6, 8.4.3, 8.6.3 | 7.2.13, 8.0.9, 8.1.7, 9.0.4 |
| CVE-2026-23479 | 2026-05-05 | High (7.7, CVSS 4.0) | redis-server | Use-after-free in the unblock client flow when a blocked client is evicted; may lead to remote code execution | 7.2 and later | 7.2.14, 7.4.9, 8.0.x: no fix, 8.2.6, 8.4.3, 8.6.3 | 7.2.13, 8.0.9, 8.1.7, 9.0.4 |
| CVE-2025-62507 | 2025-11-02 | High (7.7, CVSS 4.0) | redis-server | XACKDEL with many IDs causes a stack buffer overflow; may lead to remote code execution | 8.2.0 and later | 8.2.3 | Not listed by Valkey |
| CVE-2025-49844 | 2025-10-03 | Critical (9.9) | redis-server | Lua use-after-free in the garbage collector ("RediShell"); may lead to remote code execution | All versions with Lua scripting | 6.2.20, 7.0.x: no fix, 7.2.11, 7.4.6, 8.0.4, 8.2.2 | 7.2.11, 8.0.6, 8.1.4 |
| CVE-2025-46817 | 2025-10-03 | High (7.0) | redis-server | Lua library commands cause an integer overflow; may lead to remote code execution | All versions with Lua scripting | 6.2.20, 7.0.x: no fix, 7.2.11, 7.4.6, 8.0.4, 8.2.2 | 7.2.11, 8.0.6, 8.1.4 |
| CVE-2025-46819 | 2025-10-03 | Medium (6.3) | redis-server | Crafted Lua script reads out of bounds or crashes the server | All versions with Lua scripting | 6.2.20, 7.0.x: no fix, 7.2.11, 7.4.6, 8.0.4, 8.2.2 | 7.2.11, 8.0.6, 8.1.4 |
| CVE-2025-46818 | 2025-10-03 | Medium (6.0) | redis-server | Crafted Lua script runs code in the context of another user | All versions with Lua scripting | 6.2.20, 7.0.x: no fix, 7.2.11, 7.4.6, 8.0.4, 8.2.2 | 7.2.11, 8.0.6, 8.1.4 |
| CVE-2025-32023 | 2025-07-06 | High (7.0) | redis-server | Out-of-bounds write in HyperLogLog commands; may lead to remote code execution | 2.8 and later | 6.2.19, 7.0.x: no fix, 7.2.10, 7.4.5, 8.0.3 | 7.2.10, 8.0.4, 8.1.3 |
| CVE-2025-48367 | 2025-07-06 | High (7.5) | redis-server | Unauthenticated connections cause repeated protocol errors, starving clients (denial of service) | All versions | 6.2.19, 7.0.x: no fix, 7.2.10, 7.4.5, 8.0.3 | 7.2.10, 8.0.4, 8.1.3 |
| CVE-2025-27151 | 2025-05-27 | Medium (4.7) | redis-check-aof | Long file path overflows a stack buffer in redis-check-aof | 7.0 and later | 7.0.x: no fix, 7.2.9, 7.4.4, 8.0.2 | 7.2.10, 8.0.5, 8.1.2 |
| CVE-2025-21605 | 2025-04-23 | High (7.5) | redis-server | Unauthenticated client grows output buffers without limit until memory runs out (denial of service) | 2.6 and later | 6.2.18, 7.0.x: no fix, 7.2.8, 7.4.3 | 7.2.9, 8.0.3, 8.1.1 |
| CVE-2024-51741 | 2025-01-06 | Medium (4.4) | redis-server | Malformed ACL selector triggers a server panic (denial of service) | 7.0 and later | 7.0.x: no fix, 7.2.7, 7.4.2 | 7.2.8, 8.0.2 |
| CVE-2024-46981 | 2025-01-06 | High (7.0) | redis-server | Lua script manipulates the garbage collector; may lead to remote code execution | All versions with Lua scripting | 6.2.17, 7.0.x: no fix, 7.2.7, 7.4.2 | 7.2.8, 8.0.2 |
| CVE-2026-62356 | 2026-08-17 | High (7.5, CVSS 4.0) | RedisBloom (probabilistic types) | Integer overflow loading a Count-Min Sketch from RESTORE or RDB causes a heap out-of-bounds write | RedisBloom 2.0.0 to 2.8.23 | 8.0.x: no fix, 8.2.9, 8.4.6, 8.6.6, 8.8.2, 8.10.1 | Not applicable (Redis module) |
| CVE-2026-25589 | 2026-05-05 | High (7.7, CVSS 4.0) | RedisBloom (probabilistic types) | Invalid memory access in RESTORE with the module loaded; may lead to remote code execution | RedisBloom before 2.8.20 | 8.0.x: no fix, 8.2.6, 8.4.3, 8.6.3 | Not applicable (Redis module) |
| CVE-2026-25588 | 2026-05-05 | High (7.7, CVSS 4.0) | RedisTimeSeries (time series) | Invalid memory access in RESTORE with the module loaded; may lead to remote code execution | RedisTimeSeries before 1.12.14 | 8.0.x: no fix, 8.2.6, 8.4.3, 8.6.3 | Not applicable (Redis module) |
| CVE-2026-63639 | 2026-07-22 | High (8.8) | valkey-server | Malformed stream RESTORE payload shares one pending-entry NACK across consumers; use-after-free, possible remote code execution | 7.2.13, 8.0.9, 8.1.8, 9.0.4, 9.1.0 and earlier | Not applicable (Valkey only) | 7.2.14, 8.0.10, 8.1.9, 9.0.5, 9.1.1 |
| CVE-2026-56684 | 2026-07-22 | High (7.5) | valkey-server | Use-after-free in TLS pending-data handling triggered with CLIENT KILL | 7.2.13, 8.0.9, 8.1.8, 9.0.4, 9.1.0 and earlier | Not applicable (Valkey only) | 7.2.14, 8.0.10, 8.1.9, 9.0.5, 9.1.1 |
| CVE-2026-27623 | 2026-02-23 | High (7.5) | valkey-server | Pre-authentication denial of service from a malformed RESP request after an empty request | 9.0.0 to 9.0.2 | Not applicable (Valkey only) | 9.0.3 |
| CVE-2026-21863 | 2026-02-23 | Medium (6.5) | valkey-server | Malformed cluster bus ping extension causes an out-of-bounds read and crash | 9.0.2 and earlier | Not applicable (Valkey only) | 7.2.12, 8.0.7, 8.1.6, 9.0.3 |
| CVE-2025-67733 | 2026-02-23 | High (8.5) | valkey-server | Lua error_reply allows RESP protocol injection into another client's response stream | 9.0.1 and earlier | Not applicable (Valkey only) | 7.2.12, 8.0.7, 8.1.6, 9.0.2 |
Security fixes published without a CVE
The CVE list is not the whole security picture. From February 2026 Redis release notes list several security fixes with no CVE identifier, and Valkey published two advisories in August 2026 without one. Two of the Redis fixes have descriptions that match Valkey CVEs: the July 2026 stream RESTORE fix matches CVE-2026-63639, and the August 2026 TLS pending-data fix matches CVE-2026-56684. Treat these releases as security updates even though a CVE scanner will not flag the older build.
| Project | Released | Fix as described | First fixed releases |
|---|---|---|---|
| Redis | February 2026 | A user can inject \r\n sequences into an error reply and manipulate data read by a connection | 7.2.13, 7.4.8, 8.0.6, 8.2.5, 8.4.2, 8.6.1 |
| Redis | July 2026 | Crafted stream RESTORE payload makes two consumers share one NACK; use-after-free, possible remote code execution | 6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5 |
| Redis | July 2026 | Crafted RESTORE payloads for RedisBloom and t-digest types can trigger out-of-bounds writes | 8.2.8, 8.4.5, 8.6.5, 8.8.1 |
| Redis | August 2026 | Use-after-free in the TLS pending-data list when a command closes another pending connection | 6.2.24, 7.2.16, 7.4.11, 8.2.9, 8.4.6, 8.6.6, 8.8.2, 8.10.1 |
| Redis | August 2026 | ACL key-permission bypass in SORT, GEORADIUS and XREAD variants, where checked keys differ from accessed keys | 7.2.16, 7.4.11, 8.2.9, 8.4.6, 8.6.6, 8.8.2 |
| Redis | August 2026 | Malicious RDB payload with an out-of-range SLOT_INFO slot id corrupts memory on load; possible remote code execution | 7.4.11, 8.2.9, 8.4.6, 8.6.6, 8.8.2, 8.10.1 |
| Redis | August 2026 | TLS client certificate Common Name with an embedded NUL byte lets a client authenticate as another ACL user | 8.6.6, 8.8.2, 8.10.1 |
| Redis | September 2026 | Cluster bus has no authentication without tls-cluster; new cluster-bus-port-protected-mode option and startup warning | 8.2.10, 8.4.7, 8.6.7, 8.8.3, 8.10.2 |
| Redis | July 2025 | Multi-bulk commands from an authenticated client can cause denial of service (GHSA-2r7g-8hpc-rpq9); no fix planned | None |
| Valkey | August 2026 | Use-after-free in RDMA connection handling with CLIENT KILL; only builds with USE_RDMA and an RDMA listener (GHSA-jcj7-v34w-v9vv) | 8.0.11, 8.1.10, 9.0.6, 9.1.2 |
| Valkey | August 2026 | Unauthenticated use-after-free of the Lua interpreter state via the script debugger command cache (GHSA-fq2f-crmw-q97r) | 9.1.2 |
What this means for versions past end of life
Neither project patches a series after its end of life, and the register shows what that costs. Redis 7.0 is the clearest case: 12 of the 14 redis-server CVEs here affect it, including RediShell, and 7.0.15 will not be followed by 7.0.16. Redis 6.2 is protected today and has fixes as recent as August 2026, but its end of life is 1 April 2027; any flaw disclosed after that date stays open on 6.2. Redis 8.0, a standard release, reaches end of life on 1 December 2026 and in practice stopped receiving fixes in February 2026, so an 8.0 deployment should move to 8.2, the extended release supported to 1 September 2030. Upgrading from 6.2 or 7.0 to 7.4 or later also changes the license, from BSD-3-Clause to RSALv2 or SSPLv1 (or AGPLv3 from Redis 8), which is why some teams choose Valkey instead.
Where an upgrade cannot happen before the next disclosure, the options are a backport or compensating controls. Most rows here have an advisory workaround: ACL rules that deny EVAL, EVALSHA and FUNCTION, RESTORE, HyperLogLog or XACKDEL, plus network controls that keep unauthenticated clients off the port. AceMQ's OSSeva service publishes patched builds of Redis 6.2, 7.0 and 7.2 and Valkey 7.2 and 8.x, including Redis 7.0, which receives no upstream fixes, and 6.2 after 1 April 2027. For incident response and upgrade planning on the version you run, see Redis support and Valkey support.
How this register is maintained
Sources. The GitHub security advisories of redis/redis, valkey-io/valkey, RedisBloom/RedisBloom and RedisTimeSeries/RedisTimeSeries; the GitHub release notes of redis/redis and valkey-io/valkey, which give the fixed release in each series; NVD for every CVE identifier; redis.io version management and valkey.io release policy for support dates. Every CVE ID in the register resolves on NVD or in a GitHub advisory; CVE-2026-62356 was not yet on NVD on the date checked and is cited from its GitHub advisory.
Scope. CVEs with a publication date from 1 January 2025 to 9 October 2026, which brings in two 2024 identifiers published in January 2025. Redis Software (Redis Enterprise), Redis Cloud and the managed cloud services patch on their own schedules and are out of scope; check the vendor's bulletin. Client libraries are not tracked.
Date checked. 9 October 2026. New advisories publish without notice, so check the live advisory pages before a compliance submission. This page is re-issued when a new Redis or Valkey CVE is published.
Frequently asked questions
What is CVE-2025-49844 (RediShell)?
A use-after-free in the Lua scripting engine of Redis, published on 3 October 2025 and rated 9.9 Critical by Redis. An authenticated user with permission to run Lua scripts can trigger it and potentially execute code on the server. It affects every Redis version with Lua scripting and is fixed in Redis 6.2.20, 7.2.11, 7.4.6, 8.0.4 and 8.2.2, and in Valkey 7.2.11, 8.0.6 and 8.1.4. Redis 7.0 has no fix.
Which Redis versions are still getting security fixes?
Redis 6.2 (to 1 April 2027), 7.2 and 7.4 (to 1 December 2029), 8.2 (to 1 September 2030) and the current 8.4 to 8.10 standard releases. Redis 8.0 is listed as supported to 1 December 2026, but no 8.0.x release has shipped since February 2026. Redis 7.0 is past end of life.
Is Redis 7.0 vulnerable?
Yes. 12 of the 14 redis-server CVEs in this register affect Redis 7.0, including RediShell, and none will be fixed on 7.0. Upgrade to 7.2 or later, move to Valkey, use a backported build, or at minimum restrict the affected commands with ACLs.
Does Valkey have the same vulnerabilities as Redis?
Often, because Valkey forked from Redis 7.2.4 and shares much of the code. Thirteen of the fourteen redis-server CVEs in this register were also fixed in Valkey, most within a day or two of the Redis release. Valkey also has five CVEs of its own, and Redis-only features such as XACKDEL and the Redis 8 modules do not apply to it.
Can I cite this register?
Yes, with attribution to AceMQ and a link to this page. Every row is taken from the projects' own advisories and release notes; check them before a compliance submission, since advisories publish on an ongoing basis.
Related
Where this gets done
The work behind this page, run by the same engineers who wrote it.
- 24/7 Redis supportOpen-source Redis, Redis Stack and Valkey
- Managed Redis servicesWe run Redis and Valkey, on your infrastructure
- Redis consultingLatency, memory, replication and failover design
- Valkey supportProduction cover for the Linux Foundation fork
- Valkey consulting and licensingTanzu Valkey from an authorized Broadcom partner
- Enterprise support plansSLA tiers and what each covers
- Kubernetes and container servicesRedis on Kubernetes, operated with your team
- RabbitMQ supportIf Redis and RabbitMQ run together
Other Redis guides, comparisons and research
- GuideThe Redis Reliability GuideRead the guide
- GuideBuying Redis and Valkey Support: The GuideRead the guide
- GuideThe Redis Backup and Disaster Recovery GuideRead the guide
- GuideRedis for AI: Vector Search, Agent Memory and MCP in ProductionRead the guide
- ComparisonRedis vs Kafka ComparedSee the comparison
- ComparisonManaged Redis Options ComparedSee the comparison
Recent Redis articles
- Redis Alternatives: Open Source Options Compared (2026)Oct 2026
- Redis Cluster: Hash Slots, Sharding and OperationsOct 2026
- What Is Redis Used For? Use Cases and PersistenceOct 2026
- Redis vs Memcached: Which Cache Should You Use?Oct 2026
- Azure Cache for Redis Retirement: Dates and OptionsOct 2026
- Who Offers Valkey Support? Production Options ComparedOct 2026
Need this done on your Redis or Valkey estate?
Named senior engineers for latency, memory, replication and failover, 24/7, with a 15-minute emergency SLA.