Redis Security Advisory.
Summary
Redis issued a security advisory for a critical vulnerability affecting Redis versions used by customers and self-managed deployments. The flaw, CVE-2025-49844, allows a specially crafted Lua script to trigger a use-after-free condition that could lead to remote code execution after authentication. Redis says its cloud subscriptions have already been patched and tells self-managed users to upgrade to the latest release. The advisory also recommends restricting network access, enforcing strong authentication, and limiting permissions to reduce exposure.
Classifications
industries
No industries detected
applications
General BI
AskAI Classifications
Labels
Database Software
Cloud Infrastructure Software
Developer Tools
Linked Companies
Switch Media
$1M to $5M
Redis
$100M to $250M