Vulnerabilidades en Redis

51 resultados
Análisis Vexday

Redis apresenta um panorama de risco contido com apenas 3 CVEs registradas, nenhuma delas sob exploração ativa conhecida e sem severidade crítica. A vulnerabilidade mais recente foi publicada nos últimos 90 dias e envolve primariamente gestão inadequada de recursos (CWE-401), sugerindo risco moderado e sem indicadores de ameaça iminente.

CVE-2021-32627HIGHInteger overflow issue with Streams in RedisEPSS 4.0%CVE-2025-46817HIGHLua library commands may lead to integer overflow and potential RCEEPSS 3.7%CVE-2021-41099HIGHInteger overflow issue with strings in RedisEPSS 3.7%CVE-2021-29478HIGHVulnerability in the COPY command for large intsetsEPSS 3.6%CVE-2026-25243HIGHredis-server RESTORE invalid memory access may allow remote code executionEPSS 3.3%CVE-2022-31144HIGHPotential heap overflow in Redis EPSS 3.2%CVE-2022-35951HIGHRedis subject to Integer Overflow leading to Remote Code Execution via Heap OverflowEPSS 3.0%CVE-2026-23631MEDIUMredis-server Lua use-after-free may allow remote code executionEPSS 2.8%CVE-2021-32762HIGHInteger overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platformsEPSS 2.7%CVE-2023-41056HIGHRedis vulnerable to integer overflow in certain payloadsEPSS 2.6%CVE-2022-24735LOWLua scripts can be manipulated to overcome ACL rules in RedisEPSS 2.3%CVE-2021-32765HIGHInteger Overflow to Buffer Overflow in HiredisEPSS 2.1%CVE-2021-32672MEDIUMVulnerability in Lua Debugger in RedisEPSS 1.8%CVE-2022-24736LOWA Malformed Lua script can crash RedisEPSS 1.5%CVE-2026-23479HIGHredis-server use-after-free in unblock client flow may allow remote code executionEPSS 1.3%CVE-2025-46819MEDIUMRedis is vulnerable to DoS via specially crafted LUA scriptsEPSS 1.0%CVE-2024-31228MEDIUMDenial-of-service due to unbounded pattern matching in RedisEPSS 1.0%CVE-2023-28856MEDIUM`HINCRBYFLOAT` can be used to crash a redis-server processEPSS 1.0%CVE-2023-25155MEDIUMInteger Overflow in several Redis commands can lead to denial of service.EPSS 0.9%CVE-2025-21605HIGHRedis DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated clientEPSS 0.9%