Research · Redis

The Redis and Valkey CVE Register, 2026 Edition

Every CVE published for open-source Redis, the modules bundled into Redis 8, and Valkey between 1 January 2025 and 9 October 2026, consolidated into one register and mapped to the release series it affects. Each row is taken from the project's own GitHub security advisory and release notes and checked against NVD. It is written for the engineer who has to answer one question before a change window: is the version we run fixed, and if not, is a fix ever coming?

Tyler Eastridge

By Tyler Eastridge, Head of Operations

LinkedIn · Updated

12 min read8 sections
On this page
22
CVEs for Redis, Redis 8 modules and Valkey, January 2025 to October 2026
9.9
CVSS score of CVE-2025-49844 (RediShell), the only Critical: a Lua use-after-free in every Redis with scripting
12 of 14
redis-server CVEs in this register that affect Redis 7.0 and will never get a 7.0 fix
6
CVEs since May 2026 that affect Redis 8.0 with no 8.0.x release fixing them
What the register shows

What the register shows

22 CVEs in twenty-one months: 14 in redis-server itself, 3 in the RedisBloom and RedisTimeSeries modules that ship inside Redis 8, and 5 that Valkey disclosed for its own code. One is Critical: CVE-2025-49844, the Lua use-after-free that Wiz Research named RediShell, scored 9.9 by Redis and present in every version with Lua scripting. 15 are High and 6 Medium. Almost all of them need an authenticated connection, but four can be triggered without authentication, and most of the High rows are memory-safety bugs reachable through ordinary commands such as EVAL, RESTORE or the HyperLogLog family.

The release-series view matters more than the count. Redis 6.2, 7.2 and 7.4 received every fix that applied to them. Redis 7.0 received none: it is affected by 12 of the 14 redis-server CVEs here, and its last release, 7.0.15, predates all of them. Redis 8.0 is still listed as supported until 1 December 2026, yet no 8.0.x release has shipped since February 2026, so 6 CVEs published since May 2026 are unfixed on that line. Valkey patched every supported series, 7.2 through 9.1, for every CVE that affected it.

Severity distribution

Severity is the rating published in each GitHub security advisory, which is the CNA record for these projects. NVD sometimes scores the same CVE higher; CVE-2024-46981, for example, is 7.0 High in the Redis advisory and 9.8 Critical in NVD's own analysis. Where the ratings differ this register keeps the advisory's, as the RabbitMQ register does. The same bug can also be rated differently by each project: Valkey rates CVE-2025-49844 High (8.8) where Redis rates it Critical (9.9).

Redis, Redis 8 module and Valkey CVEs by severity, January 2025 to October 2026
SeverityCVEsShare
Critical15%
High1568%
Medium627%
Low00%
Table · Redis, Redis 8 module and Valkey CVEs by severity, January 2025 to October 2026. Scroll sideways on small screens.

CVEs by year and source

Disclosure has been steady rather than bursty: 11 in 2025 and 11 so far in 2026. The 2026 rows come in batches. Redis published three redis-server CVEs and two module CVEs together on 5 May 2026, several of them found during the Wiz Zeroday Cloud event, and Valkey released fixes for the same three redis-server bugs the following day. Lua scripting is the single largest source: six of the 14 redis-server CVEs are in the Lua engine or reachable only through scripts.

CVEs by publication year and source
Yearredis-serverRedis 8 modulesValkey onlyTotal
2025110011
202633511
Table · CVEs by publication year and source. Scroll sideways on small screens.

Redis: exposure by release series

Each row counts the CVEs in this register that affected a release of that series, and how many of them a later release in the same series fixed. A series that shipped after a fix landed, such as 8.4 for the 2025 Lua bugs, is not counted as affected. Redis 6.2 has had every applicable fix backported, most recently 6.2.24 in August 2026, and remains supported until 1 April 2027. Redis 7.0 left support in 2024 and shows 12 affected and none fixed. Redis 8.0 shows 6 unfixed: three redis-server CVEs from May 2026 and three module CVEs, all fixed on 8.2 and later. The latest-release column is the version to run, not merely the first fix.

Redis Open Source series: support status and CVE exposure in this register
SeriesCommunity end of lifeLatest release (9 Oct 2026)CVEs affecting the seriesFixed in the seriesNo fix in the series
Redis 6.21 April 20276.2.24990
Redis 7.0Past end of life; not on Redis's supported list7.0.1512012
Redis 7.21 December 20297.2.1613130
Redis 7.41 December 20297.4.1113130
Redis 8.01 December 20268.0.61376
Redis 8.21 September 20308.2.1011110
Redis 8.4Not yet set8.4.7660
Redis 8.6Not yet set8.6.7660
Redis 8.8Not yet set8.8.3110
Redis 8.10Not yet set8.10.2110
Table · Redis Open Source series: support status and CVE exposure in this register. Scroll sideways on small screens.

Valkey: exposure by release series

Valkey's policy is three years of maintenance from each minor release's first release, and five years of security support for the last minor of each major. Every series below is inside that window, and every CVE that affected a series has a fixed release on it. Valkey 7.2 and 8.0 carry the most CVEs because they predate most fixes; 9.1 shipped with the May 2026 fixes already in it. Note that Valkey 8.0.8 was revoked because its tag was placed on the wrong commit; use 8.0.9 or later.

Valkey series: support window and CVE exposure in this register
SeriesMaintenance support endsSecurity support endsLatest release (9 Oct 2026)CVEs fixed in the series
Valkey 7.216 April 202716 April 20297.2.1417
Valkey 8.015 September 202715 September 20278.0.1117
Valkey 8.131 March 202831 March 20308.1.1015
Valkey 9.021 October 202821 October 20289.0.68
Valkey 9.119 May 202919 May 20319.1.22
Table · Valkey series: support window and CVE exposure in this register. Scroll sideways on small screens.

The complete register, most recent first

Affected ranges and fixed releases are quoted from the project advisories and release notes. A fixed release is the floor, not the target: later releases in the same series include every earlier fix. "No fix" means the series was affected and no release on it contains the fix. Redis 8 modules apply to Redis 8.0 and later, where the probabilistic and time series types ship in the core distribution, and to Redis Stack builds that load the module.

All 22 CVEs in this register
CVEPublishedSeverity (CVSS)ComponentSummaryAffectedFixed in RedisFixed in Valkey
CVE-2026-252432026-05-05High (7.7, CVSS 4.0)redis-serverInvalid memory access in RESTORE with a crafted payload; may lead to remote code executionAll versions6.2.22, 7.0.x: no fix, 7.2.14, 7.4.9, 8.0.x: no fix, 8.2.6, 8.4.3, 8.6.37.2.13, 8.0.9, 8.1.7, 9.0.4
CVE-2026-236312026-05-05Medium (6.1, CVSS 4.0)redis-serverLua use-after-free during replica full sync on replicas with replica-read-only disabled; may lead to remote code execution7.0 and later7.0.x: no fix, 7.2.14, 7.4.9, 8.0.x: no fix, 8.2.6, 8.4.3, 8.6.37.2.13, 8.0.9, 8.1.7, 9.0.4
CVE-2026-234792026-05-05High (7.7, CVSS 4.0)redis-serverUse-after-free in the unblock client flow when a blocked client is evicted; may lead to remote code execution7.2 and later7.2.14, 7.4.9, 8.0.x: no fix, 8.2.6, 8.4.3, 8.6.37.2.13, 8.0.9, 8.1.7, 9.0.4
CVE-2025-625072025-11-02High (7.7, CVSS 4.0)redis-serverXACKDEL with many IDs causes a stack buffer overflow; may lead to remote code execution8.2.0 and later8.2.3Not listed by Valkey
CVE-2025-498442025-10-03Critical (9.9)redis-serverLua use-after-free in the garbage collector ("RediShell"); may lead to remote code executionAll versions with Lua scripting6.2.20, 7.0.x: no fix, 7.2.11, 7.4.6, 8.0.4, 8.2.27.2.11, 8.0.6, 8.1.4
CVE-2025-468172025-10-03High (7.0)redis-serverLua library commands cause an integer overflow; may lead to remote code executionAll versions with Lua scripting6.2.20, 7.0.x: no fix, 7.2.11, 7.4.6, 8.0.4, 8.2.27.2.11, 8.0.6, 8.1.4
CVE-2025-468192025-10-03Medium (6.3)redis-serverCrafted Lua script reads out of bounds or crashes the serverAll versions with Lua scripting6.2.20, 7.0.x: no fix, 7.2.11, 7.4.6, 8.0.4, 8.2.27.2.11, 8.0.6, 8.1.4
CVE-2025-468182025-10-03Medium (6.0)redis-serverCrafted Lua script runs code in the context of another userAll versions with Lua scripting6.2.20, 7.0.x: no fix, 7.2.11, 7.4.6, 8.0.4, 8.2.27.2.11, 8.0.6, 8.1.4
CVE-2025-320232025-07-06High (7.0)redis-serverOut-of-bounds write in HyperLogLog commands; may lead to remote code execution2.8 and later6.2.19, 7.0.x: no fix, 7.2.10, 7.4.5, 8.0.37.2.10, 8.0.4, 8.1.3
CVE-2025-483672025-07-06High (7.5)redis-serverUnauthenticated connections cause repeated protocol errors, starving clients (denial of service)All versions6.2.19, 7.0.x: no fix, 7.2.10, 7.4.5, 8.0.37.2.10, 8.0.4, 8.1.3
CVE-2025-271512025-05-27Medium (4.7)redis-check-aofLong file path overflows a stack buffer in redis-check-aof7.0 and later7.0.x: no fix, 7.2.9, 7.4.4, 8.0.27.2.10, 8.0.5, 8.1.2
CVE-2025-216052025-04-23High (7.5)redis-serverUnauthenticated client grows output buffers without limit until memory runs out (denial of service)2.6 and later6.2.18, 7.0.x: no fix, 7.2.8, 7.4.37.2.9, 8.0.3, 8.1.1
CVE-2024-517412025-01-06Medium (4.4)redis-serverMalformed ACL selector triggers a server panic (denial of service)7.0 and later7.0.x: no fix, 7.2.7, 7.4.27.2.8, 8.0.2
CVE-2024-469812025-01-06High (7.0)redis-serverLua script manipulates the garbage collector; may lead to remote code executionAll versions with Lua scripting6.2.17, 7.0.x: no fix, 7.2.7, 7.4.27.2.8, 8.0.2
CVE-2026-623562026-08-17High (7.5, CVSS 4.0)RedisBloom (probabilistic types)Integer overflow loading a Count-Min Sketch from RESTORE or RDB causes a heap out-of-bounds writeRedisBloom 2.0.0 to 2.8.238.0.x: no fix, 8.2.9, 8.4.6, 8.6.6, 8.8.2, 8.10.1Not applicable (Redis module)
CVE-2026-255892026-05-05High (7.7, CVSS 4.0)RedisBloom (probabilistic types)Invalid memory access in RESTORE with the module loaded; may lead to remote code executionRedisBloom before 2.8.208.0.x: no fix, 8.2.6, 8.4.3, 8.6.3Not applicable (Redis module)
CVE-2026-255882026-05-05High (7.7, CVSS 4.0)RedisTimeSeries (time series)Invalid memory access in RESTORE with the module loaded; may lead to remote code executionRedisTimeSeries before 1.12.148.0.x: no fix, 8.2.6, 8.4.3, 8.6.3Not applicable (Redis module)
CVE-2026-636392026-07-22High (8.8)valkey-serverMalformed stream RESTORE payload shares one pending-entry NACK across consumers; use-after-free, possible remote code execution7.2.13, 8.0.9, 8.1.8, 9.0.4, 9.1.0 and earlierNot applicable (Valkey only)7.2.14, 8.0.10, 8.1.9, 9.0.5, 9.1.1
CVE-2026-566842026-07-22High (7.5)valkey-serverUse-after-free in TLS pending-data handling triggered with CLIENT KILL7.2.13, 8.0.9, 8.1.8, 9.0.4, 9.1.0 and earlierNot applicable (Valkey only)7.2.14, 8.0.10, 8.1.9, 9.0.5, 9.1.1
CVE-2026-276232026-02-23High (7.5)valkey-serverPre-authentication denial of service from a malformed RESP request after an empty request9.0.0 to 9.0.2Not applicable (Valkey only)9.0.3
CVE-2026-218632026-02-23Medium (6.5)valkey-serverMalformed cluster bus ping extension causes an out-of-bounds read and crash9.0.2 and earlierNot applicable (Valkey only)7.2.12, 8.0.7, 8.1.6, 9.0.3
CVE-2025-677332026-02-23High (8.5)valkey-serverLua error_reply allows RESP protocol injection into another client's response stream9.0.1 and earlierNot applicable (Valkey only)7.2.12, 8.0.7, 8.1.6, 9.0.2
Table · All 22 CVEs in this register. Scroll sideways on small screens.

Security fixes published without a CVE

The CVE list is not the whole security picture. From February 2026 Redis release notes list several security fixes with no CVE identifier, and Valkey published two advisories in August 2026 without one. Two of the Redis fixes have descriptions that match Valkey CVEs: the July 2026 stream RESTORE fix matches CVE-2026-63639, and the August 2026 TLS pending-data fix matches CVE-2026-56684. Treat these releases as security updates even though a CVE scanner will not flag the older build.

Security fixes listed in release notes or advisories without a CVE ID, to 9 October 2026
ProjectReleasedFix as describedFirst fixed releases
RedisFebruary 2026A user can inject \r\n sequences into an error reply and manipulate data read by a connection7.2.13, 7.4.8, 8.0.6, 8.2.5, 8.4.2, 8.6.1
RedisJuly 2026Crafted stream RESTORE payload makes two consumers share one NACK; use-after-free, possible remote code execution6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5
RedisJuly 2026Crafted RESTORE payloads for RedisBloom and t-digest types can trigger out-of-bounds writes8.2.8, 8.4.5, 8.6.5, 8.8.1
RedisAugust 2026Use-after-free in the TLS pending-data list when a command closes another pending connection6.2.24, 7.2.16, 7.4.11, 8.2.9, 8.4.6, 8.6.6, 8.8.2, 8.10.1
RedisAugust 2026ACL key-permission bypass in SORT, GEORADIUS and XREAD variants, where checked keys differ from accessed keys7.2.16, 7.4.11, 8.2.9, 8.4.6, 8.6.6, 8.8.2
RedisAugust 2026Malicious RDB payload with an out-of-range SLOT_INFO slot id corrupts memory on load; possible remote code execution7.4.11, 8.2.9, 8.4.6, 8.6.6, 8.8.2, 8.10.1
RedisAugust 2026TLS client certificate Common Name with an embedded NUL byte lets a client authenticate as another ACL user8.6.6, 8.8.2, 8.10.1
RedisSeptember 2026Cluster bus has no authentication without tls-cluster; new cluster-bus-port-protected-mode option and startup warning8.2.10, 8.4.7, 8.6.7, 8.8.3, 8.10.2
RedisJuly 2025Multi-bulk commands from an authenticated client can cause denial of service (GHSA-2r7g-8hpc-rpq9); no fix plannedNone
ValkeyAugust 2026Use-after-free in RDMA connection handling with CLIENT KILL; only builds with USE_RDMA and an RDMA listener (GHSA-jcj7-v34w-v9vv)8.0.11, 8.1.10, 9.0.6, 9.1.2
ValkeyAugust 2026Unauthenticated use-after-free of the Lua interpreter state via the script debugger command cache (GHSA-fq2f-crmw-q97r)9.1.2
Table · Security fixes listed in release notes or advisories without a CVE ID, to 9 October 2026. Scroll sideways on small screens.

What this means for versions past end of life

Neither project patches a series after its end of life, and the register shows what that costs. Redis 7.0 is the clearest case: 12 of the 14 redis-server CVEs here affect it, including RediShell, and 7.0.15 will not be followed by 7.0.16. Redis 6.2 is protected today and has fixes as recent as August 2026, but its end of life is 1 April 2027; any flaw disclosed after that date stays open on 6.2. Redis 8.0, a standard release, reaches end of life on 1 December 2026 and in practice stopped receiving fixes in February 2026, so an 8.0 deployment should move to 8.2, the extended release supported to 1 September 2030. Upgrading from 6.2 or 7.0 to 7.4 or later also changes the license, from BSD-3-Clause to RSALv2 or SSPLv1 (or AGPLv3 from Redis 8), which is why some teams choose Valkey instead.

Where an upgrade cannot happen before the next disclosure, the options are a backport or compensating controls. Most rows here have an advisory workaround: ACL rules that deny EVAL, EVALSHA and FUNCTION, RESTORE, HyperLogLog or XACKDEL, plus network controls that keep unauthenticated clients off the port. AceMQ's OSSeva service publishes patched builds of Redis 6.2, 7.0 and 7.2 and Valkey 7.2 and 8.x, including Redis 7.0, which receives no upstream fixes, and 6.2 after 1 April 2027. For incident response and upgrade planning on the version you run, see Redis support and Valkey support.

How this register is maintained

Sources. The GitHub security advisories of redis/redis, valkey-io/valkey, RedisBloom/RedisBloom and RedisTimeSeries/RedisTimeSeries; the GitHub release notes of redis/redis and valkey-io/valkey, which give the fixed release in each series; NVD for every CVE identifier; redis.io version management and valkey.io release policy for support dates. Every CVE ID in the register resolves on NVD or in a GitHub advisory; CVE-2026-62356 was not yet on NVD on the date checked and is cited from its GitHub advisory.

Scope. CVEs with a publication date from 1 January 2025 to 9 October 2026, which brings in two 2024 identifiers published in January 2025. Redis Software (Redis Enterprise), Redis Cloud and the managed cloud services patch on their own schedules and are out of scope; check the vendor's bulletin. Client libraries are not tracked.

Date checked. 9 October 2026. New advisories publish without notice, so check the live advisory pages before a compliance submission. This page is re-issued when a new Redis or Valkey CVE is published.

Frequently asked questions

What is CVE-2025-49844 (RediShell)?

A use-after-free in the Lua scripting engine of Redis, published on 3 October 2025 and rated 9.9 Critical by Redis. An authenticated user with permission to run Lua scripts can trigger it and potentially execute code on the server. It affects every Redis version with Lua scripting and is fixed in Redis 6.2.20, 7.2.11, 7.4.6, 8.0.4 and 8.2.2, and in Valkey 7.2.11, 8.0.6 and 8.1.4. Redis 7.0 has no fix.

Which Redis versions are still getting security fixes?

Redis 6.2 (to 1 April 2027), 7.2 and 7.4 (to 1 December 2029), 8.2 (to 1 September 2030) and the current 8.4 to 8.10 standard releases. Redis 8.0 is listed as supported to 1 December 2026, but no 8.0.x release has shipped since February 2026. Redis 7.0 is past end of life.

Is Redis 7.0 vulnerable?

Yes. 12 of the 14 redis-server CVEs in this register affect Redis 7.0, including RediShell, and none will be fixed on 7.0. Upgrade to 7.2 or later, move to Valkey, use a backported build, or at minimum restrict the affected commands with ACLs.

Does Valkey have the same vulnerabilities as Redis?

Often, because Valkey forked from Redis 7.2.4 and shares much of the code. Thirteen of the fourteen redis-server CVEs in this register were also fixed in Valkey, most within a day or two of the Redis release. Valkey also has five CVEs of its own, and Redis-only features such as XACKDEL and the Redis 8 modules do not apply to it.

Can I cite this register?

Yes, with attribution to AceMQ and a link to this page. Every row is taken from the projects' own advisories and release notes; check them before a compliance submission, since advisories publish on an ongoing basis.

Redis services

Where this gets done

The work behind this page, run by the same engineers who wrote it.

More resources

Other Redis guides, comparisons and research

From the blog

Recent Redis articles

Next step

Need this done on your Redis or Valkey estate?

Named senior engineers for latency, memory, replication and failover, 24/7, with a 15-minute emergency SLA.