Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-21605

Redis output buffers grow without limit for an unauthenticated client

Technology

Redis

CVSS Score

7.5 / 10.0

Affected Versions

2.6 and later, before 6.2.18, 7.2.8 and 7.4.3

Upstream Fix

6.2.18, 7.2.8, 7.4.3

Published

April 23, 2025

OSSeva Coverage

Fixed upstream

Description

The default configuration does not limit the output buffer of normal clients, and a client that has not authenticated can keep it growing with the NOAUTH responses to its commands until the server runs out of memory or is killed. Network access controls or TLS client certificates mitigate it. The 7.5 score on NVD is from GitHub as CNA.

Upstream record: NVD · CVE.org

Is your Redis deployment affected?

If you're running 2.6 and later, before 6.2.18, 7.2.8 and 7.4.3, you need this patch. Book a discovery call to get covered.