CVE-2025-67733 describes a vulnerability in Valkey, a distributed key-value database, prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12. A malicious user can exploit improper handling of null characters in Lua script error handling to inject arbitrary data into the client's response stream, potentially corrupting or tampering with data for other users on the same connection. This vulnerability has a CVSS score of 7.1 (HIGH), indicating a network-based attack with low complexity and privileges, leading to a high impact on availability and low impact on integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.2.12CPE matchmatch criteria | cpe:2.3:a:lfprojects:valkey:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.0.7CPE matchmatch criteria | cpe:2.3:a:lfprojects:valkey:*:*:*:*:*:*:*:* | ||
>= 8.1.0, < 8.1.6CPE matchmatch criteria | cpe:2.3:a:lfprojects:valkey:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.2CPE matchmatch criteria | cpe:2.3:a:lfprojects:valkey:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Valkey vulnerabilities
Mar 18, 2026USN-8106-1: Valkey vulnerabilities
Mar 18, 2026Valkey: Valkey: Data tampering and denial of service via improper null character handling in Lua scripts
Feb 23, 2026Valkey Affected by RESP Protocol Injection via Lua error_reply
Feb 10, 2026