Redis Labs maintains a focused but prominently deployed in-memory data-structure platform whose core products—Redis, RedisGraph, and the Hiredis client library—are embedded across caching, session management, and real-time analytics workloads in production environments worldwide. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency toward public exploit availability, reflecting the memory-safety and input-parsing demands of high-performance C codebases. The exposure recurs through weakness classes including integer overflow, out-of-bounds writes, improper input validation, memory-buffer boundary violations, and NULL-pointer dereferences—patterns characteristic of native storage engines handling untrusted protocol data at scale. Defenders should treat Redis platform updates as high-priority despite the vendor's narrow product scope, since the software's prevalence in infrastructure and data-handling roles means a single critical flaw can propagate across numerous downstream deployments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Redislabs over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11218CRITICAL Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overfl | Jun 17, 2018 | 9.8 | 73 | NO | YES |
CVE-2018-12453HIGH Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the | Jun 16, 2018 | 7.5 | 47 | NO | YES |
CVE-2021-32761HIGH Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prio | Jul 21, 2021 | 7.5 | 41 | NO | NO |
CVE-2019-10192HIGH A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a | Jul 11, 2019 | 7.2 | 37 | NO | NO |
CVE-2018-12326HIGH Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line | Jun 17, 2018 | 8.4 | 37 | NO | YES |
CVE-2016-8339CRITICAL A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the c | Oct 28, 2016 | 9.8 | 37 | NO | NO |
CVE-2019-10193HIGH A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperlog | Jul 11, 2019 | 7.2 | 36 | NO | NO |
CVE-2018-11219CRITICAL An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bound | Jun 17, 2018 | 9.8 | 32 | NO | NO |
CVE-2017-15047CRITICAL The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspecif | Oct 6, 2017 | 9.8 | 31 | NO | NO |
CVE-2023-47003CRITICAL An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlock_ItemIsDeleted. | Nov 16, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Redislabs.
Media articles that mention a CVE ID that affects a product developed by Redislabs — matched by CVE ID, not by vendor name.