Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-46817

Redis Lua library commands allow an integer overflow that may lead to remote code execution

Technology

Redis

CVSS Score

8.8 / 10.0

Affected Versions

All versions with Lua scripting before 6.2.20, 7.2.11, 7.4.6, 8.0.4 and 8.2.2

Upstream Fix

6.2.20, 7.2.11, 7.4.6, 8.0.4, 8.2.2

Published

October 3, 2025

OSSeva Coverage

Fixed upstream

Description

An authenticated user can use a crafted Lua script to cause an integer overflow that may lead to remote code execution. It was fixed in the same releases as CVE-2025-49844. Blocking scripts with ACLs on both the EVAL and FUNCTION command families mitigates it.

Upstream record: NVD · CVE.org

Is your Redis deployment affected?

If you're running All versions with Lua scripting before 6.2.20, 7.2.11, 7.4.6, 8.0.4 and 8.2.2, you need this patch. Book a discovery call to get covered.