// OSSeva Blog
SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
The short answer
Redis ships each security fix on several release lines at once. In 2026 the fixes have gone to 6.2, 7.2, 7.4 and the 8.x lines from 8.2 upward. According to the version management page on redis.io, 6.2 is supported until 1 April 2027, 7.2 and 7.4 until 1 December 2029, and 8.2 until 1 September 2030. Redis 7.0 reached end of life on 29 July 2024, and its last release, 7.0.15, came out in January 2024. Redis 8.0 is listed as supported until 1 December 2026, yet no 8.0 release has shipped since 8.0.6 in February 2026, so the May 2026 fixes have no 8.0 build. The most serious recent flaw is CVE-2025-49844, a Lua use-after-free that NVD scores 9.9. It is fixed in 6.2.20, 7.2.11, 7.4.6, 8.0.4 and 8.2.2, and never on 7.0.
Licences, briefly
The version you run also sets the licence. Redis 7.2 and every earlier line are BSD-3-Clause, and patch releases on 6.2 and 7.2 keep that licence. Redis 7.4 moved to a dual RSALv2 or SSPLv1 licence, and Redis 8.0 added AGPLv3 as a third option. Valkey, the Linux Foundation project forked from Redis 7.2.4, stays BSD-3-Clause. For most estates this narrows the upgrade targets rather than blocking them, but it means a move from 7.2 to 7.4 needs a licence review as well as a test plan. See Redis 7.2 end of life for the dates on the last BSD line.
Security releases since October 2024
Redis publishes most fixes as GitHub security advisories and lists the CVEs in the release notes of every line it patches. This table is built from those release notes.
| Release date | Fixed versions | CVEs |
|---|---|---|
| 2 October 2024 | 6.2.16, 7.2.6, 7.4.1 | CVE-2024-31449, CVE-2024-31228; CVE-2024-31227 on 7.x only |
| 6 January 2025 | 6.2.17, 7.2.7, 7.4.2 | CVE-2024-46981; CVE-2024-51741 on 7.x only |
| 23 April 2025 | 6.2.18, 7.2.8, 7.4.3 | CVE-2025-21605 |
| 6 July 2025 | 6.2.19, 7.2.10, 7.4.5, 8.0.3 | CVE-2025-32023, CVE-2025-48367 |
| 3 October 2025 | 6.2.20, 7.2.11, 7.4.6, 8.0.4, 8.2.2 | CVE-2025-49844, CVE-2025-46817, CVE-2025-46818, CVE-2025-46819 |
| 2 November 2025 | 8.2.3 | CVE-2025-62507 |
| 5 May 2026 | 6.2.22; 7.2.14, 7.4.9; 8.2.6, 8.4.3, 8.6.3 | CVE-2026-25243 on every line; CVE-2026-23479 and CVE-2026-23631 on 7.2 and later; CVE-2026-25588 and CVE-2026-25589 on 8.x |
Redis 6.2.22 carries only CVE-2026-25243, because the advisories for CVE-2026-23479 and CVE-2026-23631 list 7.2 and 7.0 respectively as the first affected versions. The two 8.x-only CVEs from May are in the bundled modules: CVE-2026-25588 in RedisTimeSeries before 1.12.14 and CVE-2026-25589 in RedisBloom before 2.8.20, both 8.8 on NVD. Later releases also carry security fixes. The 17 August 2026 releases (6.2.24, 7.2.16, 7.4.11 and 8.2.9 to 8.10.1) fixed a use-after-free on every line and ACL key permission bypasses on 7.2 and later, and the 8.x releases name one CVE that NVD had not published at the time of writing. The 8.x releases of 17 September 2026 added a startup warning, and an option to refuse to start, when the cluster bus port has no authentication.
Notable Redis CVEs by release line
CVSS is NVD's own score where NVD has analysed the record, otherwise the score from the CNA, which for Redis is GitHub. The fixed versions come from the release notes, which are more precise than the NVD ranges for the 2026 records.
| CVE | Issue | CVSS | 6.2 | 7.2 | 7.4 | 8.x | 7.0 |
|---|---|---|---|---|---|---|---|
| CVE-2025-49844 | Lua use-after-free through the garbage collector lets an authenticated user run code | 9.9 | 6.2.20 | 7.2.11 | 7.4.6 | 8.0.4, 8.2.2 | Not patched |
| CVE-2024-46981 | Lua garbage collector manipulation leads to code execution | 9.8 | 6.2.17 | 7.2.7 | 7.4.2 | Fixed before 8.0 | Not patched |
| CVE-2026-25243 | Invalid memory access in RESTORE with a crafted serialized value | 8.8 | 6.2.22 | 7.2.14 | 7.4.9 | 8.2.6, 8.4.3, 8.6.3; no 8.0 build | Not patched |
| CVE-2026-23479 | Use-after-free when a blocked client is evicted while its command is re-executed | 8.8 | Not affected | 7.2.14 | 7.4.9 | 8.2.6, 8.4.3, 8.6.3; no 8.0 build | Not affected |
| CVE-2025-62507 | Stack buffer overflow in XACKDEL with many IDs | 8.8 | Not affected | Not affected | Not affected | 8.2.3 | Not affected |
| CVE-2025-46817 | Integer overflow in Lua library commands | 8.8 | 6.2.20 | 7.2.11 | 7.4.6 | 8.0.4, 8.2.2 | Not patched |
| CVE-2024-31449 | Stack overflow in the Lua bit library | 8.8 | 6.2.16 | 7.2.6 | 7.4.1 | Fixed before 8.0 | Not patched |
| CVE-2026-23631 | Lua use-after-free on replicas with replica-read-only disabled | 8.1 | Not affected | 7.2.14 | 7.4.9 | 8.2.6, 8.4.3, 8.6.3; no 8.0 build | Not patched |
| CVE-2023-41056 | Integer overflow when resizing memory buffers leads to heap overflow | 8.1 | Not affected | 7.2.4 | Not affected | Not affected | 7.0.15 (7.0.9 to 7.0.14 affected) |
| CVE-2025-32023 | Out-of-bounds write in HyperLogLog commands | 7.8 | 6.2.19 | 7.2.10 | 7.4.5 | 8.0.3 | Not patched |
| CVE-2025-21605 | An unauthenticated client grows its output buffer until memory runs out | 7.5 (GitHub) | 6.2.18 | 7.2.8 | 7.4.3 | Fixed in 8.0.0 | Not patched |
| CVE-2025-48367 | Repeated protocol errors from an unauthenticated connection starve other clients | 7.5 (GitHub) | 6.2.19 | 7.2.10 | 7.4.5 | 8.0.3 | Not patched |
"Not patched" means the line is affected and no release on it carries the fix. All of these need an authenticated client except CVE-2025-21605 and CVE-2025-48367, which are denial of service from a connection that has not authenticated.
CVE-2025-49844, the Lua use-after-free
CVE-2025-49844 was published on 3 October 2025. Wiz, whose researchers reported it, named it RediShell. A user who is allowed to run Lua scripts can send one that manipulates the garbage collector, triggers a use-after-free and can then run code on the server. The advisory says the bug exists in every Redis version with Lua scripting, and NVD scores it 9.9. It is not in CISA's Known Exploited Vulnerabilities catalogue.
Three more Lua CVEs came out the same day: CVE-2025-46817 (8.8), CVE-2025-46818 (7.3) and CVE-2025-46819 (7.1). All four are fixed together in 6.2.20, 7.2.11, 7.4.6, 8.0.4 and 8.2.2. The advisories give a workaround for servers that cannot be upgraded at once: use ACLs to stop users running scripts, by restricting EVAL and EVALSHA and, for the other three, the FUNCTION command family as well. Valkey has its own fixes for CVE-2025-49844, in 7.2.11, 8.0.6 and 8.1.4.
The one Redis CVE in the KEV catalogue
CVE-2022-0543 (10.0) is the only Redis entry in CISA's Known Exploited Vulnerabilities catalogue, added on 28 March 2022. It is a Lua sandbox escape caused by how Debian and Ubuntu packaged Redis, not a flaw in upstream Redis, so it affects servers installed from those distribution packages before their fixed builds. Check the package version as well as the Redis version on any Debian-family host.
What each line gets
Redis 8.x
Redis 8.2 has the latest published end date in the 8 series, 1 September 2030. 8.4, 8.6, 8.8 and 8.10 have each had security releases in 2026, and 8.10.2 is the newest release at the time of writing. Redis 8.0 is the exception: redis.io lists it as supported until 1 December 2026, but its last release is 8.0.6 from February 2026, so it has no fix for CVE-2026-25243, CVE-2026-23479 or CVE-2026-23631. A server on 8.0 should move to 8.2 or later.
Redis 7.4
Redis 7.4 is supported until 1 December 2029 and has been patched in every security release in the table. The latest release is 7.4.11. It is the first line under RSALv2 or SSPLv1.
Redis 7.2
Redis 7.2 is supported until 1 December 2029 and is the last BSD-3-Clause line. It has been patched in every security release in the table, and the latest release is 7.2.16. A server below 7.2.14 is missing the fixes for three remote code execution CVEs from May 2026. See Redis 7.2 end of life.
Redis 7.0
Redis 7.0 reached end of life on 29 July 2024, the day 7.4 was released, and 7.0.15 is its final release. Every Redis CVE in the table published after that date, apart from those limited to 7.2 or 8.x, affects 7.0 with no upstream fix. That includes CVE-2025-49844 at 9.9, CVE-2024-46981 at 9.8, CVE-2026-25243 at 8.8 and the unauthenticated denial of service in CVE-2025-21605. See Redis 7.0 end of life.
Redis 6.2
Redis 6.2 still gets fixes, and the latest release is 6.2.24 from 17 August 2026. Several of the 2026 CVEs do not reach it because the code they affect arrived in 7.0 or 7.2. That support ends on 1 April 2027, about six months away, and after that 6.2 will be in the position 7.0 is in now. See Redis 6.2 end of life.
Redis 6.0 and older
Redis 6.0 reached end of life in May 2022 with 6.0.20 as its final release. It is affected by everything 6.2 has been patched for since then.
What to do on each line
- 8.x, 7.4 and 7.2. Stay on the newest patch release of the line. The minimum for the 2026 RCE fixes is 7.2.14, 7.4.9, 8.2.6, 8.4.3 or 8.6.3.
- 8.0. Move to 8.2, which has the longest support window in the 8 series.
- 6.2. Upgrade to 6.2.24 now and plan the move off 6.2 before 1 April 2027. If you need to keep the BSD licence, 7.2 or Valkey are the targets.
- 7.0 and 6.0. Upgrade, or take patched builds from a supplier that backports fixes. Until then, restrict EVAL, EVALSHA, FUNCTION and RESTORE with ACLs, and keep the port reachable only by the applications that use it.
Where OSSeva fits
Redis upgrades are usually cheap, and for most estates the right answer is the newest patch release on a supported line. Where an appliance, a vendor product or a licence requirement pins the version, OSSeva backports Redis CVE fixes to 6.2.x and 7.0.x and ships them under the original BSD licence. They are available now on the Patch, Assure and Operate tiers. Assure adds security hardening and compliance documentation, and Operate adds 24/7 monitoring with a 15-minute SLA and named Redis engineers. See Redis support and the Redis end of life tracker.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026SecurityApache Solr Vulnerabilities by Version: CVEs for Solr 7, 8, 9 and 10
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.