28,678 Entries 2,229 Sources 5 Verticals Last sync 6 minutes Live
OS & platform

Redis

Redis
8.2.7 frisch latest release
04.06.2026

Upgrade assessment

Sicherheitsrelevant

Zeitnah aktualisieren

30 CVE(s) zuletzt, höchste Schwere: kritisch

Derived automatically from release, repo and CVE data — no judgment by a language model.

Specsattributes
gh_etagW/"10eb732be893fe17e431f39d20011047d8fd0488ebbc9cbd3f2e5f34c21f32a0"
eol_productredis
gh_checked_at2026-06-08T01:45:00.121232+00:00
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
OS & platform High

A vulnerability in Redis allows authenticated attackers to gain full root access to all servers in a CVX cluster if they have network access and the Redis password.

CVE-2025-5088
06.06.2026
CVE
OS & platform Medium

A vulnerability in OpenTelemetry eBPF instrumentation for Redis causes error messages to be transmitted unfiltered to telemetry systems, potentially exposing confidential data or attacker-controlled content to monitoring backends.

CVE-2026-45679
06.06.2026
CVE
OS & platform Medium

In the Budibase low-code platform, user permissions are not immediately removed from Redis cache after role revocation, allowing users to retain access to functions they should no longer have privileges for up to one hour.

CVE-2026-46424
06.06.2026
CVE
OS & platform Medium

A vulnerability in the Redis server component of Synology BeeDrive for desktop allows local users to access certain files or directories to perform denial-of-service attacks and crash the service.

CVE-2024-11399
06.06.2026
CVE
OS & platform Low

A vulnerability in Roundcube Webmail allows attackers to delete arbitrary files without authentication by manipulating session data in Redis or Memcache storage systems.

CVE-2026-48847
06.06.2026
CVE
OS & platform Low

CVE-2026-9357

CVE-2026-9357
06.06.2026
CVE
OS & platform Critical

A security vulnerability in the LiteSpeed User-End cPanel Plugin allows attackers to escalate their privileges and potentially gain full system control, which has already been actively exploited.

CVE-2026-48172
06.06.2026
CVE
OS & platform High

AutoGPT, an AI workflow platform, unsafely deserializes data from Redis cache without integrity checks. Attackers can execute arbitrary code by manipulating the cache.

CVE-2026-33233
06.06.2026
CVE
OS & platform High

A vulnerability in Open WebUI before version 0.9.0 causes configuration settings from different instances to overwrite each other when sharing Redis databases, potentially exposing users to incorrect server configurations from other instances.

CVE-2026-44552
06.06.2026
CVE
OS & platform Medium

A vulnerability in the Netty library allows attackers to inject malicious Redis commands by using special control characters in messages that are not properly filtered.

CVE-2026-42586
06.06.2026
CVE
OS & platform Medium

In the Inbox Zero email software, a Redis implementation flaw can cause email thread events from one user to be incorrectly delivered to another logged-in user, leading to unauthorized data access.

CVE-2026-42865
06.06.2026
CVE
OS & platform High

A vulnerability in the RedisBloom module for Redis allows authenticated attackers to trigger memory errors and potentially execute malicious code by providing crafted data through the RESTORE command.

affects: <2.8.20 · 8.2.7 not affected

CVE-2026-25589
06.06.2026
CVE
OS & platform High

A vulnerability in the RedisTimeSeries module for Redis allows authenticated attackers to trigger memory errors and potentially execute malicious code by providing crafted data through the RESTORE command.

affects: <1.12.14 · 8.2.7 not affected

CVE-2026-25588
06.06.2026
CVE
OS & platform High

Redis database has a vulnerability in the RESTORE command that doesn't properly validate incoming data. Attackers with access can send malicious data and potentially execute arbitrary code on the server.

affects: <8.6.3 · your 8.2.7 affected

CVE-2026-25243
06.06.2026
CVE
OS & platform High

Redis database has a vulnerability in its Lua scripting feature that allows authenticated attackers to execute malicious code on replica servers when certain write permissions are enabled.

affects: <8.6.3 · your 8.2.7 affected

CVE-2026-23631
06.06.2026
CVE
OS & platform High

Redis server versions 7.2.0 through 8.6.3 contain a memory handling flaw when processing blocked commands that allows authenticated attackers to execute malicious code on the server.

affects: ≥7.2.0 <8.6.3 · your 8.2.7 affected

CVE-2026-23479
06.06.2026
CVE
OS & platform Critical

A vulnerability in OpenC3 COSMOS allows users with script permissions to perform administrative actions through specially crafted scripts, including reading secrets from the Redis database and modifying system settings.

CVE-2026-42088
06.06.2026
CVE
OS & platform Critical

A critical vulnerability in the MixPHP Framework allows attackers to execute malicious code by injecting manipulated data into Redis sessions or cache storage, which is then unsafely deserialized.

CVE-2026-42472
06.06.2026
CVE
OS & platform Critical

A security vulnerability in the mailcow email software allows attackers to inject malicious code into admin logs that gets executed when administrators view those logs.

CVE-2026-40872
06.06.2026
CVE
OS & platform High

A vulnerability in Distribution software allows deleted container content to become accessible again when Redis cache and delete functionality are enabled.

CVE-2026-35172
06.06.2026
CVE
OS & platform Critical

A vulnerability in D-Tale (a web application for data analysis) allows attackers to execute malicious code on the server when Redis or Shelf storage layers are used.

CVE-2026-35052
06.06.2026
CVE
OS & platform Critical

A vulnerability in Aperi'Solve allows attackers to execute arbitrary code and gain full system control through unsanitized password inputs when uploading JPEG files.

CVE-2026-34977
06.06.2026
CVE
OS & platform Low

A vulnerability in Roundcube Webmail allows unauthenticated attackers to write arbitrary files on the server by sending manipulated session data through the Redis/Memcache handler.

CVE-2026-35537
06.06.2026
CVE
OS & platform High

FastGPT, an AI agent platform, has a vulnerability in certain endpoints that allows authenticated attackers to scan internal networks and access internal services like databases.

CVE-2026-34163
06.06.2026
CVE
OS & platform High

A WordPress plugin vulnerability allows attackers to send arbitrary web requests to internal services without authentication, potentially leading to remote server access.

CVE-2026-1648
06.06.2026
CVE
OS & platform Medium

A vulnerability in LangGraph's caching system allows execution of malicious code when attackers can write data to the cache storage (like Redis or SQLite) and the application later processes it.

CVE-2026-27794
06.06.2026
CVE
OS & platform Medium

A vulnerability in datapizza-ai software allows attackers on the local network to inject and execute malicious data through the Redis cache function.

CVE-2026-2970
06.06.2026
CVE
OS & platform Critical

OneUptime monitoring software allows users to execute JavaScript code that can easily escape its security sandbox, enabling complete system access and exposure of all stored passwords and credentials.

CVE-2026-27574
06.06.2026
CVE
OS & platform Medium

A vulnerability in the Redis checkpoint library for LangGraph allows attackers to manipulate database queries through specially crafted filter inputs and potentially access unauthorized data.

CVE-2026-27022
06.06.2026
CVE
OS & platform Medium

LibreNMS, a network monitoring tool, has an input validation weakness in device group names that allows administrators to inject malicious scripts that get displayed to other users.

CVE-2026-26991
06.06.2026
REL
OS & platform frisch

Release 2026-06-04

8.2.7
04.06.2026
REL
OS & platform frisch

Release 2026-06-04

8.4.4
04.06.2026
REL
OS & platform frisch

Release 2026-06-04

8.6.4
04.06.2026
REL
OS & platform bewährt

Release 2026-05-25

8.8.0
25.05.2026
EOL
OS & platform

Current / stable

8.8
25.05.2026
REL
OS & platform bewährt

Release 2026-05-14

8.8-rc1
14.05.2026
REL
OS & platform bewährt

Release 2026-05-05

6.2.22
05.05.2026
REL
OS & platform bewährt

Release 2026-05-05

7.2.14
05.05.2026
REL
OS & platform bewährt

Release 2026-05-05

7.4.9
05.05.2026
REL
OS & platform bewährt

Release 2026-05-05

8.2.6
05.05.2026
REL
OS & platform bewährt

Release 2026-05-05

8.4.3
05.05.2026
REL
OS & platform bewährt

Release 2026-05-05

8.6.3
05.05.2026
REL
OS & platform bewährt

Release 2026-04-28

8.8-m03
28.04.2026
REL
OS & platform bewährt

Release 2026-04-16

8.8-m02
16.04.2026
REL
OS & platform bewährt

Release 2026-03-24

8.6.2
24.03.2026
REL
OS & platform bewährt

Release 2026-02-23

7.2.13
23.02.2026
REL
OS & platform bewährt

Release 2026-02-23

7.4.8
23.02.2026
REL
OS & platform bewährt

Release 2026-02-23

8.0.6
23.02.2026
REL
OS & platform bewährt

Release 2026-02-23

8.2.5
23.02.2026
REL
OS & platform bewährt

Release 2026-02-23

8.4.2
23.02.2026
REL
OS & platform bewährt

Release 2026-02-23

8.6.1
23.02.2026
EOL
OS & platform

Supported

8.6
11.02.2026
REL
OS & platform bewährt

Release 2026-02-10

8.6.0
10.02.2026
REL
OS & platform bewährt

Release 2026-02-08

8.2.4
08.02.2026
REL
OS & platform bewährt

Release 2026-02-08

8.4.1
08.02.2026
REL
OS & platform bewährt

Release 2026-01-22

8.6-rc1
22.01.2026
REL
OS & platform bewährt

Release 2025-11-18

8.4.0
18.11.2025
EOL
OS & platform

Supported

8.4
18.11.2025
REL
OS & platform bewährt

Release 2025-11-04

8.4-rc1
04.11.2025
REL
OS & platform bewährt

Release 2025-11-02

7.2.12
02.11.2025
REL
OS & platform bewährt

Release 2025-11-02

7.4.7
02.11.2025
REL
OS & platform bewährt

Release 2025-11-02

8.0.5
02.11.2025
REL
OS & platform bewährt

Release 2025-11-02

8.2.3
02.11.2025
EOL
OS & platform

EOL 2026-05-25

8.2
04.08.2025
EOL
OS & platform

EOL 2026-02-11

8.0
02.05.2025
EOL
OS & platform

Supported

7.4
29.07.2024
EOL
OS & platform

Supported

7.2
15.08.2023
EOL
OS & platform

EOL 2024-07-29

7.0
27.04.2022
EOL
OS & platform

Supported

6.2
22.02.2021
EOL
OS & platform

EOL 2022-05-31

6.0
30.04.2020
EOL
OS & platform

EOL 2022-04-27

5.0
17.10.2018