Redis is an in-memory data store and caching layer deeply embedded across web applications, microservices, and real-time systems, where its compact codebase and network exposure create a high-value target despite a narrow product portfolio. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the memory-safety and parsing demands of a C-based system handling untrusted network input. The recurring exposure centers on integer overflow, buffer overflow, and improper input validation across the core Redis server and language-specific client libraries such as redis-py and hiredis, weakness classes typical of low-level data-structure and protocol-parsing code. Defenders should prioritize Redis instances exposed to untrusted networks and maintain close attention to security updates, as the vendor's ubiquity in caching tiers makes its flaws broadly consequential; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Redis over time
Signals from CVEs in this vendor scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0543CRITICAL It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code exec | Feb 18, 2022 | 10.0 | 98 | YES | YES |
CVE-2025-49844CRITICAL Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garb | Oct 3, 2025 | 9.9 | 83 | NO | NO |
CVE-2023-36824HIGH Redis is an in-memory database that persists on disk. In Redit 7.0 prior to 7.0.12, extracting key names from a command and a list of arguments may, in some cases, trigger a heap o | Jul 11, 2023 | 8.8 | 69 | NO | NO |
CVE-2023-22458MEDIUM Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of- | Jan 20, 2023 | 5.5 | 58 | NO | NO |
CVE-2022-24834HIGH Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corru | Jul 13, 2023 | 8.8 | 50 | NO | NO |
CVE-2022-36021MEDIUM Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially crafted pattern to trigger a den | Mar 1, 2023 | 5.5 | 50 | NO | NO |
CVE-2023-28425MEDIUM Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime ass | Mar 20, 2023 | 5.5 | 49 | NO | NO |
CVE-2026-23479HIGH Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when | May 5, 2026 | 8.8 | 45 | NO | NO |
CVE-2026-25243HIGH Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker wit | May 5, 2026 | 8.8 | 42 | NO | NO |
CVE-2025-32023HIGH Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to | Jul 7, 2025 | 7.8 | 40 | NO | YES |
Signals from CVEs in this vendor scope (51 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Redis.
Media articles that mention a CVE ID that affects a product developed by Redis — matched by CVE ID, not by vendor name.