Redisson is a Java-based distributed object and services framework that provides an in-memory data structure library for Redis, with its vulnerability profile centered on a single product exhibiting deserialization weaknesses. The deserialization of untrusted data represents the durable structural risk inherent to a library that handles serialized objects from remote or untrusted sources, a pattern that persists across versions of the framework; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Redisson over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42809HIGH Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received from the Redis server contain Java objects that the client des | Oct 4, 2023 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Redisson.
Media articles that mention a CVE ID that affects a product developed by Redisson — matched by CVE ID, not by vendor name.