cbcvebase.
CVE-2025-48367
published 2025-07-07

CVE-2025-48367: Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client…

PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.73%
50.6th percentile
Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianredict< redict 7.3.5+ds-1 (forky)redict 7.3.5+ds-1 (forky)
debianredis< redict 7.3.5+ds-1 (forky)redict 7.3.5+ds-1 (forky)
debianvalkey< redict 7.3.5+ds-1 (forky)redict 7.3.5+ds-1 (forky)
lfprojectsvalkey>= 0 < 8.1.1+dfsg1-38.1.1+dfsg1-3
lfprojectsvalkey>= 0 < 8.1.1+dfsg1-38.1.1+dfsg1-3
msrcazl3_valkey_8.0.3-3_on_azure_linux_3.0
msrcazl3_valkey_8.0.4-1_on_azure_linux_3.0
msrccbl2_redis_6.2.18-1_on_cbl_mariner_2.0
msrccm2_redis_6.2.18-3_on_cbl_mariner_2.0
redisredis< 6.2.196.2.19
redisredis
redisredis
redisredis
redisredis>= 0 < 5:6.0.16-1+deb11u75:6.0.16-1+deb11u7
redisredis>= 0 < 5:7.0.15-1~deb12u55:7.0.15-1~deb12u5
redisredis>= 0 < 5:8.0.2-25:8.0.2-2
redisredis>= 0 < 5:8.0.2-25:8.0.2-2
redisredis>= 7.0 < 7.2.107.2.10
redisredis>= 7.4.0 < 7.4.57.4.5
redisredis>= 8.0.0 < 8.0.38.0.3

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.