CVE-2025-67733
published 2026-02-23CVE-2025-67733: Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary…
PriorityP342high7.1CVSS 3.1
AVNACLPRLUINSUCNILAH
EPSS
0.59%
43.9th percentile
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | redict | < valkey 8.1.4+dfsg1-2 (forky) | valkey 8.1.4+dfsg1-2 (forky) |
| debian | redis | < valkey 8.1.4+dfsg1-2 (forky) | valkey 8.1.4+dfsg1-2 (forky) |
| debian | valkey | < valkey 8.1.4+dfsg1-2 (forky) | valkey 8.1.4+dfsg1-2 (forky) |
| lfprojects | valkey | < 7.2.12 | 7.2.12 |
| lfprojects | valkey | >= 0 < 8.1.1+dfsg1-3+deb13u2 | 8.1.1+dfsg1-3+deb13u2 |
| lfprojects | valkey | >= 0 < 8.1.4+dfsg1-2 | 8.1.4+dfsg1-2 |
| lfprojects | valkey | >= 0 < 7.2.12+dfsg1-0ubuntu0.1 | 7.2.12+dfsg1-0ubuntu0.1 |
| lfprojects | valkey | >= 0 < 8.1.6+dfsg1-0ubuntu0.1 | 8.1.6+dfsg1-0ubuntu0.1 |
| lfprojects | valkey | >= 8.0.0 < 8.0.7 | 8.0.7 |
| lfprojects | valkey | >= 8.1.0 < 8.1.6 | 8.1.6 |
| lfprojects | valkey | >= 9.0.0 < 9.0.2 | 9.0.2 |
| msrc | azl3_valkey_8.0.6-1_on_azure_linux_3.0 | — | — |
| valkey-io | valkey | < 7.2.12 | 7.2.12 |
| valkey-io | valkey | — | — |
| valkey-io | valkey | — | — |
| valkey-io | valkey | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
osv7.1HIGH
vendor_debian8.5HIGH
vendor_msrc8.5HIGH
vendor_redhat8.5HIGH
vendor_ubuntu8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
valkey vulnerabilities
osv·2026-03-18·CVSS 7.1
CVE-2025-67733 [HIGH] valkey vulnerabilities
valkey vulnerabilities
It was discovered that Valkey incorrectly handled errors for lua scripts.
An attacker could possibly use this issue to inject arbitrary information
into the response stream for other clients. (CVE-2025-67733)
It was discovered that Valkey incorrectly handled malformed cluster bus
messages. A remote attacker could possibly use this issue to cause Valkey
to crash, resulting in a denial of service. (CVE-2026-21863)
OSV
CVE-2025-67733: Valkey is a distributed key-value database
osv·2026-02-23·CVSS 7.1
CVE-2025-67733 [HIGH] CVE-2025-67733: Valkey is a distributed key-value database
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.
Ubuntu
Valkey vulnerabilities
vendor_ubuntu·2026-03-18·CVSS 8.5
CVE-2025-67733 [HIGH] Valkey vulnerabilities
Title: Valkey vulnerabilities
Summary: Several security issues were fixed in Valkey.
It was discovered that Valkey incorrectly handled errors for lua scripts.
An attacker could possibly use this issue to inject arbitrary information
into the response stream for other clients. (CVE-2025-67733)
It was discovered that Valkey incorrectly handled malformed cluster bus
messages. A remote attacker could possibly use this issue to cause Valkey
to crash, resulting in a denial of service. (CVE-2026-21863)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Red Hat
Valkey: Valkey: Data tampering and denial of service via improper null character handling in Lua scripts
vendor_redhat·2026-02-23·CVSS 8.5
CVE-2025-67733 [HIGH] CWE-170 Valkey: Valkey: Data tampering and denial of service via improper null character handling in Lua scripts
Valkey: Valkey: Data tampering and denial of service via improper null character handling in Lua scripts
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.
A flaw was found in Valkey, a distributed key-value database. A malicious user can exploit this vulnerability by using scripting commands to inject arbitrary information into the response stream. This is caused by improper handling of null characte
Microsoft
Valkey Affected by RESP Protocol Injection via Lua error_reply
vendor_msrc·2026-02-10·CVSS 8.5
CVE-2025-67733 [HIGH] CWE-74 Valkey Affected by RESP Protocol Injection via Lua error_reply
Valkey Affected by RESP Protocol Injection via Lua error_reply
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2025-67733: redict - Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0....
vendor_debian·2025·CVSS 8.5
CVE-2025-67733 [HIGH] CVE-2025-67733: redict - Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0....
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.
Scope: local
forky: open
sid: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-67733 Valkey: Valkey: Data tampering and denial of service via improper null character handling in Lua scripts
bugzilla·2026-02-23·CVSS 7.1
CVE-2025-67733 [HIGH] CVE-2025-67733 Valkey: Valkey: Data tampering and denial of service via improper null character handling in Lua scripts
CVE-2025-67733 Valkey: Valkey: Data tampering and denial of service via improper null character handling in Lua scripts
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:3443 https://access.redhat.com/errata/RHSA-2026:3443
---
This issue has been addressed in the following products:
Re
Wiz
CVE-2026-27623 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.9
CVE-2026-27623 [CRITICAL] CVE-2026-27623 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27623 :
Valkey vulnerability analysis and mitigation
Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can cause the system to abort by triggering an assertion. When processing incoming requests, the Valkey system does not properly reset the networking state after processing an empty request. A malicious actor can then send a request that the server incorrectly identifies as breaking server side invariants, which results in the server shutting down. Version 9.0.3 fixes the issue. As an additional mitigation, properly isolate Valkey deployments so that only trusted users have access.
Source : NVD
## 7.5
Score
Published February 23, 2026
Severity HIGH
CNA Score 7.5
Affected
Wiz
CVE-2026-21863 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-21863 [HIGH] CVE-2026-21863 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21863 :
Redis vulnerability analysis and mitigation
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.
Source : NVD
## 7.5
Score
Published February 23, 2026
Severity HIGH
CNA Score 7.5
Wiz
CVE-2025-67733 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.5
CVE-2025-67733 [HIGH] CVE-2025-67733 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67733 :
Redis vulnerability analysis and mitigation
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.
Source : NVD
## 7.1
Score
Published February 23, 2026
Severity HIGH
CNA Score 8.5
Affected Technologies
Redis
Rocky Linux
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploita
https://github.com/valkey-io/valkey/security/advisories/GHSA-p876-p7q5-hv2mhttps://access.redhat.com/errata/RHSA-2026:3443https://access.redhat.com/errata/RHSA-2026:3507https://access.redhat.com/errata/RHSA-2026:5445https://access.redhat.com/security/cve/CVE-2025-67733https://bugzilla.redhat.com/show_bug.cgi?id=2442025https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-67733.json
2026-02-23
Published