Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Redis

First CVE: Oct 4, 2021Active for: 5 yearsTotal CVEs: 51
72.5
VTI Score
TOP TARGET

Redis is an in-memory data store and caching layer deeply embedded across web applications, microservices, and real-time systems, where its compact codebase and network exposure create a high-value target despite a narrow product portfolio. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the memory-safety and parsing demands of a C-based system handling untrusted network input. The recurring exposure centers on integer overflow, buffer overflow, and improper input validation across the core Redis server and language-specific client libraries such as redis-py and hiredis, weakness classes typical of low-level data-structure and protocol-parsing code. Defenders should prioritize Redis instances exposed to untrusted networks and maintain close attention to security updates, as the vendor's ubiquity in caching tiers makes its flaws broadly consequential; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
51
Total CVEs
More Total CVEs than 98% of tracked vendors
2.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
2.0%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Redis over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2021
4 years ago
Most Recent CVE
May 5, 2026
80 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (51 CVEs).

51 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-0543CRITICAL
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code exec
Feb 18, 202210.098YESYES
CVE-2025-49844CRITICAL
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garb
Oct 3, 20259.983NONO
CVE-2023-36824HIGH
Redis is an in-memory database that persists on disk. In Redit 7.0 prior to 7.0.12, extracting key names from a command and a list of arguments may, in some cases, trigger a heap o
Jul 11, 20238.869NONO
CVE-2023-22458MEDIUM
Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-
Jan 20, 20235.558NONO
CVE-2022-24834HIGH
Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corru
Jul 13, 20238.850NONO
CVE-2022-36021MEDIUM
Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially crafted pattern to trigger a den
Mar 1, 20235.550NONO
CVE-2023-28425MEDIUM
Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime ass
Mar 20, 20235.549NONO
CVE-2026-23479HIGH
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when
May 5, 20268.845NONO
CVE-2026-25243HIGH
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker wit
May 5, 20268.842NONO
CVE-2025-32023HIGH
Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to
Jul 7, 20257.840NOYES
View all 51 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products51 CVEs
10%
25%
51%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local14 (27.5%)
Network36 (70.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.0%)
Attack Complexity
Low43 (84.3%)
High8 (15.7%)
Unknown0 (0.0%)
User Interaction
None49 (96.1%)
Unknown0 (0.0%)
Required2 (3.9%)
Privileges Required
Low34 (66.7%)
High2 (3.9%)
None15 (29.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (51 CVEs).

CISA KEV
1 CVE
2.0% of CVEs· 99th percentile
Metasploit
1 CVE
2.0% of CVEs· 97th percentile
Nuclei
1 CVE
2.0% of CVEs· 95th percentile
ExploitDB
1 CVE
2.0% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Redis.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Redis — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Redis's Products

View all 4 CNAs →

Top CWEs