← Vulnerability feed

Vulnerability record · CVE-2022-36021 · published 1 March 2023

CVE-2022-36021: Redis string matching commands allow authenticated denial of service

Redis · Redis

Redis string matching commands such as SCAN and KEYS can be invoked with a specially crafted pattern that causes the server to hang and consume 100% CPU. The flaw is a resource consumption issue (CWE-407) fixed in Redis 6.0.18, 6.2.11 and 7.0.9. It matters because a single authenticated user can stall a shared in-memory database that many applications depend on.

5.5 CVSS 3.1 Medium EPSS 60% · top 0.9% CWE-407 · CWE-407
5.5CVSS 3.1 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang and consume 100% CPU time. The problem is fixed in Redis versions 6.0.18, 6.2.11, 7.0.9.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityThe flaw is an authenticated denial of service with no confidentiality or integrity impact, but the high EPSS score and public patch make it worth prompt remediation.

What it is

Redis string matching commands such as SCAN and KEYS can be invoked with a specially crafted pattern that causes the server to hang and consume 100% CPU. The flaw is a resource consumption issue (CWE-407) fixed in Redis 6.0.18, 6.2.11 and 7.0.9. It matters because a single authenticated user can stall a shared in-memory database that many applications depend on.

Impact

An attacker with valid Redis credentials can drive the server to 100% CPU and hang it, denying service to all other clients and dependent applications. There is no data confidentiality or integrity impact; the effect is availability loss.

Attack surface

The flaw is reached through normal Redis commands (SCAN, KEYS) sent to the server, so it requires an authenticated connection but no user interaction. The CVSS vector AV:L/PR:L/UI:N reflects local access with low privileges, though any client able to issue commands can trigger it.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at 0.605 (99.1st percentile), indicating elevated predicted exploitation activity. The advisory and patch commits are public, so the technique is discoverable.

What to do

  • Upgrade Redis to 6.0.18, 6.2.11, 7.0.9 or later; patched versions are the only complete fix.
  • Restrict who can authenticate to Redis and avoid exposing the service to untrusted networks.
  • Disable or rename dangerous commands such as KEYS where application requirements allow.
  • Apply CPU and connection limits or timeouts so a single client cannot monopolize the server.
  • Monitor for repeated SCAN or KEYS calls with unusual patterns from a single client.

Detection

  • Alert on sustained Redis CPU near 100% correlated with SCAN or KEYS command activity.
  • Use Redis slowlog or command monitoring to flag repeated SCAN/KEYS calls with complex or wildcard-heavy patterns.
  • Baseline normal SCAN/KEYS usage per client and alert on deviations or bursts from one connection.
  • Watch for client connections that remain open while the server stops responding to other clients.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36021 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-0543Debian-packaged Redis Lua sandbox escape allows remote code executionA Debian-specific packaging flaw in Redis leaves the Lua interpreter's sandbox improperly restricted, allowing escape from the Lua sandbox. Because R…KEVEPSS 99%analysed9.9CVE-2025-49844Redis Lua scripting use-after-free enables remote code executionRedis versions 8.2.1 and below contain a use-after-free in the Lua scripting engine. An authenticated user can supply a crafted Lua script that manip…EPSS 82%analysed9.8CVE-2025-27151Redis improper input validation vulnerabilityRedis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exi…EPSS 0.95%9.8CVE-2024-46981Redis use after free vulnerabilityRedis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the gar…EPSS 8.2%9.8CVE-2022-3734Redis untrusted search path vulnerabilityA vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Pro…EPSS 0.65%9.8CVE-2022-35951Redis integer overflow vulnerabilityRedis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `X…EPSS 3.9%8.8CVE-2025-46817Redis integer overflow vulnerabilityRedis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu…EPSS 3.8%8.8CVE-2024-31449Redis improper input validation vulnerabilityRedis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack bu…EPSS 4.5%

Source: NIST National Vulnerability Database (record CVE-2022-36021), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.