Back to Vulnerability Directory
HIGHFixed upstream
CVE-2025-21605
Redis output buffers grow without limit for an unauthenticated client
Technology
Redis
CVSS Score
7.5 / 10.0
Affected Versions
2.6 and later, before 6.2.18, 7.2.8 and 7.4.3
Upstream Fix
6.2.18, 7.2.8, 7.4.3
Published
April 23, 2025
OSSeva Coverage
Fixed upstream
Description
The default configuration does not limit the output buffer of normal clients, and a client that has not authenticated can keep it growing with the NOAUTH responses to its commands until the server runs out of memory or is killed. Network access controls or TLS client certificates mitigate it. The 7.5 score on NVD is from GitHub as CNA.
Is your Redis deployment affected?
If you're running 2.6 and later, before 6.2.18, 7.2.8 and 7.4.3, you need this patch. Book a discovery call to get covered.