Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2025-46819Integer Overflow or Wraparound in Redis

Severity
7.1HIGHNVD
OSV8.8
EPSS
5.0%
top 10.22%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 3
Latest updateMar 24

Description

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LUA script to read out-of-bound data or crash the server and subsequent denial of service. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to block a scri

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages21 packages

CVEListV5redis/redis< 8.2.2
NVDredis/redis7.07.2.11+4
debiandebian/redis< redict 7.3.6+ds-1 (forky)
Debianredis/redis< 5:6.0.16-1+deb11u8+3

Patches

🔴Vulnerability Details

2
OSV
valkey vulnerabilities2025-11-26
OSV
CVE-2025-46819: Redis is an open source, in-memory database that persists on disk2025-10-03

💥Exploits & PoCs

1
Nuclei
Redis < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds Read

📋Vendor Advisories

6
CISA ICS
Schneider Electric Plant iT/Brewmaxx2026-03-24
Ubuntu
Valkey vulnerabilities2025-11-26
Microsoft
Redis is vulnerable to DoS via specially crafted LUA scripts2025-10-14
Red Hat
Redis: Redis is vulnerable to DoS via specially crafted LUA scripts2025-10-03
Debian
CVE-2025-46819: redict - Redis is an open source, in-memory database that persists on disk. Versions 8.2....2025

🕵️Threat Intelligence

3
Bleepingcomputer
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws2025-10-14
Wiz
CVE-2026-21863 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2025-67733 Impact, Exploitability, and Mitigation Steps | Wiz