Vulnerabilities in Redis and Valkey databases

Corrective releases for the Redis DBMS (6.2.19, 7.2.10, 7.4.5, 8.0.3) and Valkey (8.0.4, 8.1.3) have been published, addressing two vulnerabilities. The most dangerous vulnerability (CVE-2025-32023) could potentially lead to remote code execution on the server due to data being written outside the allocated buffer. To exploit this vulnerability, an attacker must be able to send commands to the DBMS.

The issue is caused by an error in the implementation of commands that use the HyperLogLog algorithm for approximate counting of unique elements in a set. By submitting a specially crafted string, an attacker can initiate a buffer overflow. This problem affects all Redis versions that support HLL commands. As a workaround, user access to HLL commands can be restricted through ACL.

The second vulnerability (CVE-2025-48367) can be exploited by an authenticated user to cause a denial of service or degrade the performance of the DBMS. This issue arises from improper error handling during connection establishment.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster