Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-32023

Redis HyperLogLog commands allow an out-of-bounds write

Technology

Redis

CVSS Score

7.8 / 10.0

Affected Versions

2.8 and later, before 6.2.19, 7.2.10, 7.4.5 and 8.0.3

Upstream Fix

6.2.19, 7.2.10, 7.4.5, 8.0.3

Published

July 7, 2025

OSSeva Coverage

Fixed upstream

Description

An authenticated user can send a crafted string that triggers a stack or heap out-of-bounds write in HyperLogLog operations, which may lead to remote code execution. Restricting the HLL commands with ACLs mitigates it.

Upstream record: NVD · CVE.org

Is your Redis deployment affected?

If you're running 2.8 and later, before 6.2.19, 7.2.10, 7.4.5 and 8.0.3, you need this patch. Book a discovery call to get covered.