Search CVE reports


Toggle filters

1 – 10 of 88 results


CVE-2026-84372

Medium priority
Needs evaluation

(Predis is a flexible and feature-complete Redis and Valkey client for ...)

1 affected package

php-nrk-predis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-nrk-predis Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-81934

Medium priority
Needs evaluation

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-72568

Medium priority
Not affected

Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-66373

Medium priority
Needs evaluation

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-25589

Medium priority
Needs evaluation

RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-25588

Medium priority
Needs evaluation

RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-25243

Medium priority
Needs evaluation

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-23631

Medium priority
Needs evaluation

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-23479

Medium priority
Needs evaluation

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-62507

Medium priority
Not affected

Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's and trigger a stack buffer overflow, which may potentially lead to remote code...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages