Redis Issues Security Advisory for Five Critical Vulnerabilities Including Remote Code Execution Risks
The Redis community and Redis organization have released a critical security advisory addressing five distinct vulnerabilities identified in their software. These flaws, tracked as CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, and CVE-2026-23631, pose significant security risks, with four rated as High severity (CVSS 7.7) and one as Medium (CVSS 6.1). The vulnerabilities primarily involve use-after-free errors and invalid memory access issues within the RESTORE command and Lua scripting mechanisms. Exploitation by authenticated users could lead to remote code execution, potentially resulting in full system compromise, data exfiltration, or service disruption. Specific modules like RedisTimeSeries and RedisBloom are also affected. Redis Cloud customers are already protected via automatic upgrades. However, users managing self-hosted Redis Software, Open Source, or Community editions are urged to update their instances immediately to the remediated versions indicated in the advisory. This proactive measure aims to maintain safety, security, and compliance posture for all Redis deployments globally.
Wire timeline
Redis Issues Security Advisory for Five Critical Vulnerabilities Including Remote Code Execution Risks
The Redis community and Redis organization have released a critical security advisory addressing five distinct vulnerabilities identified in their software. These flaws, tracked as CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, and CVE-2026-23631, pose significant security risks, with four rated as High severity (CVSS 7.7) and one as Medium (CVSS 6.1). The vulnerabilities primarily involve use-after-free errors and invalid memory access issues within the RESTORE command and Lua scripting mechanisms. Exploitation by authenticated users could lead to remote code execution, potentially resulting in full system compromise, data exfiltration, or service disruption. Specific modules like RedisTimeSeries and RedisBloom are also affected. Redis Cloud customers are already protected via automatic upgrades. However, users managing self-hosted Redis Software, Open Source, or Community editions are urged to update their instances immediately to the remediated versions indicated in the advisory. This proactive measure aims to maintain safety, security, and compliance posture for all Redis deployments globally.
Redis Blog