Back to Vulnerability Directory
HIGHFixed upstream
CVE-2025-46817
Redis Lua library commands allow an integer overflow that may lead to remote code execution
Technology
Redis
CVSS Score
8.8 / 10.0
Affected Versions
All versions with Lua scripting before 6.2.20, 7.2.11, 7.4.6, 8.0.4 and 8.2.2
Upstream Fix
6.2.20, 7.2.11, 7.4.6, 8.0.4, 8.2.2
Published
October 3, 2025
OSSeva Coverage
Fixed upstream
Description
An authenticated user can use a crafted Lua script to cause an integer overflow that may lead to remote code execution. It was fixed in the same releases as CVE-2025-49844. Blocking scripts with ACLs on both the EVAL and FUNCTION command families mitigates it.
Is your Redis deployment affected?
If you're running All versions with Lua scripting before 6.2.20, 7.2.11, 7.4.6, 8.0.4 and 8.2.2, you need this patch. Book a discovery call to get covered.