Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-48367

Redis unauthenticated connections can starve other clients with repeated protocol errors

Technology

Redis

CVSS Score

7.5 / 10.0

Affected Versions

All versions before 6.2.19, 7.2.10, 7.4.5 and 8.0.3

Upstream Fix

6.2.19, 7.2.10, 7.4.5, 8.0.3

Published

July 7, 2025

OSSeva Coverage

Fixed upstream

Description

An unauthenticated connection can cause repeated IP protocol errors that starve other clients and end in denial of service. The 7.5 score on NVD is from GitHub as CNA.

Upstream record: NVD · CVE.org

Is your Redis deployment affected?

If you're running All versions before 6.2.19, 7.2.10, 7.4.5 and 8.0.3, you need this patch. Book a discovery call to get covered.