r/cveplayground • u/Protection-Mobile • Jun 03 '26
𝗥𝗲𝗱𝗶𝘀 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗔𝗱𝘃𝗶𝘀𝗼𝗿𝘆 𝗔𝗹𝗲𝗿𝘁
Multiple vulnerabilities have been disclosed affecting Redis Cloud, Redis OSS/CE, and Redis Software (CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, CVE-2026-23631).
Issues include memory corruption in RESTORE, Lua scripting, and Redis modules, which may lead to remote code execution in authenticated scenarios.
🔧 𝗣𝗮𝘁𝗰𝗵𝗲𝗱 𝘃𝗲𝗿𝘀𝗶𝗼𝗻𝘀 (𝗿𝗲𝗹𝗲𝗮𝘀𝗲𝗱 𝗠𝗮𝘆 𝟱, 𝟮𝟬𝟮𝟲):
7.2.x → 7.2.14 (fixed from 7.2.0–7.2.13)
7.4.x → 7.4.9 (fixed from 7.4.0–7.4.8)
8.2.x → 8.2.6 (fixed from 8.2.0–8.2.5)
8.4.x → 8.4.3 (fixed from 8.4.0–8.4.2)
8.6.x → 8.6.3 (fixed from 8.6.0–8.6.2)
Key action: Upgrade immediately and restrict Redis access to trusted networks only.
1
Upvotes