← Vulnerability feed

Vulnerability record · CVE-2025-46819 · published 3 October 2025

CVE-2025-46819: Redis integer overflow vulnerability

Redis · Redis

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LUA script to read out-of-bound data or crash the server and subsequent denial of service. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to block a script by restricting both the EVAL and FUNCTION command families.

7.1 CVSS 3.1 High EPSS 1.1% · top 36.8% CWE-190 · Integer overflowCWE-125 · Out-of-bounds read
7.1CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LUA script to read out-of-bound data or crash the server and subsequent denial of service. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to block a script by restricting both the EVAL and FUNCTION command families.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-46819 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-0543Debian-packaged Redis Lua sandbox escape allows remote code executionA Debian-specific packaging flaw in Redis leaves the Lua interpreter's sandbox improperly restricted, allowing escape from the Lua sandbox. Because R…KEVEPSS 99%analysed9.9CVE-2025-49844Redis Lua scripting use-after-free enables remote code executionRedis versions 8.2.1 and below contain a use-after-free in the Lua scripting engine. An authenticated user can supply a crafted Lua script that manip…EPSS 82%analysed9.8CVE-2025-27151Redis improper input validation vulnerabilityRedis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exi…EPSS 0.95%9.8CVE-2024-46981Redis use after free vulnerabilityRedis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the gar…EPSS 8.2%9.8CVE-2022-3734Redis untrusted search path vulnerabilityA vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Pro…EPSS 0.65%9.8CVE-2022-35951Redis integer overflow vulnerabilityRedis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `X…EPSS 3.9%8.8CVE-2025-46817Redis integer overflow vulnerabilityRedis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu…EPSS 3.8%8.8CVE-2024-31449Redis improper input validation vulnerabilityRedis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack bu…EPSS 4.5%

Source: NIST National Vulnerability Database (record CVE-2025-46819), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.