Redis Security Advisory.

General News

Summary

Redis issued a security advisory for a critical vulnerability affecting Redis versions used by customers and self-managed deployments. The flaw, CVE-2025-49844, allows a specially crafted Lua script to trigger a use-after-free condition that could lead to remote code execution after authentication. Redis says its cloud subscriptions have already been patched and tells self-managed users to upgrade to the latest release. The advisory also recommends restricting network access, enforcing strong authentication, and limiting permissions to reduce exposure.

Classifications

industries
No industries detected
applications
General BI

AskAI Classifications

Labels
Database Software Cloud Infrastructure Software Developer Tools

Linked Companies

Switch Media
$1M to $5M
Redis
$100M to $250M