PatchSiren

Redis CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Redis CVE published 2026-08-10

CVE-2026-72568

The CVE-2026-72568 vulnerability is an out-of-bounds read issue in Redis through 8.8.1. It allows an adjacent unauthenticated attacker to cause denial of service or information disclosure by sending a specially crafted PING message to the Redis Cluster Bus port. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Administrators and users of Redis instances, especially those expos [truncated]

HIGH redis CVE published 2026-05-05

CVE-2026-25243

CVE-2026-25243 is a high-severity vulnerability in Redis, an in-memory data structure store. The RESTORE command does not properly validate serialized values, allowing an authenticated attacker with permission to execute RESTORE to supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with AC [truncated]

MEDIUM redis CVE published 2026-05-05

CVE-2026-23631

CVE-2026-23631 is a use-after-free vulnerability in Redis, an in-memory data structure store. An authenticated attacker can exploit the master-replica synchronization mechanism to trigger this vulnerability on replicas where replica-read-only is disabled or can be disabled, potentially leading to remote code execution. The vulnerability is patched in Redis version 8.6.3. As a workaround, users can prevent [truncated]

Known exploited Redis CVE published 2022-03-28

CVE-2022-0543

CVE-2022-0543 is a Debian-specific Redis vulnerability described as a Lua sandbox escape and listed by CISA in the Known Exploited Vulnerabilities (KEV) catalog. Because it is officially marked as known exploited, affected Debian-packaged Redis deployments should be treated as a high-priority remediation item. CISA’s guidance for this entry is to apply updates per vendor instructions.