← Vulnerability feed

Vulnerability record · CVE-2023-22458 · published 20 January 2023

CVE-2023-22458: Redis HRANDFIELD/ZRANDMEMBER assertion crash denial of service

Redis · Redis

Redis versions 6.2 and 7.0 before 6.2.9 and 7.0.8 crash on an assertion failure when an authenticated user issues HRANDFIELD or ZRANDMEMBER with specially crafted arguments, rooted in an integer overflow (CWE-190). Because Redis is commonly a shared in-memory data store, a crash takes down the whole instance and any dependent services. No workarounds exist; upgrading is the only fix.

5.5 CVSS 3.1 Medium EPSS 72% · top 0.6% CWE-190 · Integer overflow
5.5CVSS 3.1 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityThe flaw only causes denial of service and requires authentication, but the high EPSS score and lack of workarounds raise its operational urgency.

What it is

Redis versions 6.2 and 7.0 before 6.2.9 and 7.0.8 crash on an assertion failure when an authenticated user issues HRANDFIELD or ZRANDMEMBER with specially crafted arguments, rooted in an integer overflow (CWE-190). Because Redis is commonly a shared in-memory data store, a crash takes down the whole instance and any dependent services. No workarounds exist; upgrading is the only fix.

Impact

An attacker with valid credentials can crash the Redis server, causing a denial of service for all clients and applications relying on that instance. There is no data confidentiality or integrity impact per the CVSS vector.

Attack surface

Reached over the Redis command interface by an authenticated user sending crafted HRANDFIELD or ZRANDMEMBER arguments; no user interaction is required. The CVSS vector is AV:L, indicating the scoring assumes local access, though the flaw is triggered through commands.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at roughly 0.72 (99th percentile), suggesting elevated likelihood of attempted exploitation.

What to do

  • Upgrade Redis to 6.2.9 or 7.0.8 (or later) as the primary fix.
  • If immediate upgrade is impossible, restrict command access via ACLs to remove HRANDFIELD and ZRANDMEMBER from untrusted users.
  • Enforce strong authentication and least-privilege Redis ACLs so only trusted clients can issue commands.
  • Isolate Redis from untrusted networks and avoid exposing it directly to the internet.
  • Monitor for repeated crashes and restart loops as an indicator of attempted abuse.

Detection

  • Alert on Redis process crashes or assertion failures in server logs, especially around HRANDFIELD or ZRANDMEMBER.
  • Monitor for HRANDFIELD and ZRANDMEMBER commands with unusual or oversized arguments via command logging or slowlog.
  • Track unexpected Redis restarts or availability gaps in monitoring.
  • Watch for repeated authentication and command patterns from a single client preceding a crash.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-22458 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-0543Debian-packaged Redis Lua sandbox escape allows remote code executionA Debian-specific packaging flaw in Redis leaves the Lua interpreter's sandbox improperly restricted, allowing escape from the Lua sandbox. Because R…KEVEPSS 99%analysed9.9CVE-2025-49844Redis Lua scripting use-after-free enables remote code executionRedis versions 8.2.1 and below contain a use-after-free in the Lua scripting engine. An authenticated user can supply a crafted Lua script that manip…EPSS 82%analysed9.8CVE-2025-27151Redis improper input validation vulnerabilityRedis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exi…EPSS 0.95%9.8CVE-2024-46981Redis use after free vulnerabilityRedis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the gar…EPSS 8.2%9.8CVE-2022-3734Redis untrusted search path vulnerabilityA vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Pro…EPSS 0.65%9.8CVE-2022-35951Redis integer overflow vulnerabilityRedis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `X…EPSS 3.9%8.8CVE-2025-46817Redis integer overflow vulnerabilityRedis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu…EPSS 3.8%8.8CVE-2024-31449Redis improper input validation vulnerabilityRedis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack bu…EPSS 4.5%

Source: NIST National Vulnerability Database (record CVE-2023-22458), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.