Vulnerabilidades em redis
51 resultadosAnálise Vexday
O Redis apresenta 47 vulnerabilidades catalogadas, com apenas 1 crítica e nenhuma sob ataque ativo conhecido, indicando risco moderado e manejável. A fraqueza dominante é overflow de inteiros (CWE-190), pattern clássico que exige atenção em atualizações; as 3 publicações recentes (últimos 90 dias) sugerem atividade contínua de descoberta, mantendo o fornecedor no radar de monitoramento.
CVE-2023-25155MEDIUMInteger Overflow in several Redis commands can lead to denial of service.EPSS 0.9%CVE-2026-66373HIGHRedis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE paylEPSS 0.9%CVE-2025-21605HIGHRedis DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated clientEPSS 0.9%CVE-2025-29923LOWgo-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishmentEPSS 0.7%CVE-2025-46818MEDIUMRedis: Authenticated users can execute LUA scripts as a different userEPSS 0.7%CVE-2026-81934HIGHRedis TLS pending-data list use-after-freeEPSS 0.7%CVE-2023-45145LOWRedis Unix-domain socket may have be exposed with the wrong permissions for a short time window.EPSS 0.4%CVE-2024-31227MEDIUMDenial-of-service due to malformed ACL selectors in RedisEPSS 0.4%CVE-2024-51741MEDIUMRedis allows denial-of-service due to malformed ACL selectorsEPSS 0.3%CVE-2023-41053LOWRedis SORT_RO may bypass ACL configurationEPSS 0.3%CVE-2025-46686LOWRedis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs beEPSS 0.3%