← Vulnerability feed

Vulnerability record · CVE-2025-49844 · published 3 October 2025

CVE-2025-49844: Redis Lua scripting use-after-free enables remote code execution

Redis · Redis

Redis versions 8.2.1 and below contain a use-after-free in the Lua scripting engine. An authenticated user can supply a crafted Lua script that manipulates the garbage collector to trigger the flaw, potentially achieving remote code execution. The issue affects all Redis versions with Lua scripting and is fixed in 8.2.2.

9.9 CVSS 3.1 Critical EPSS 82% · top 0.3% CWE-416 · Use after free
9.9CVSS 3.1 base score
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.9 with network reachability, low privileges, scope change, and high EPSS make this a top remediation priority despite no KEV listing.

What it is

Redis versions 8.2.1 and below contain a use-after-free in the Lua scripting engine. An authenticated user can supply a crafted Lua script that manipulates the garbage collector to trigger the flaw, potentially achieving remote code execution. The issue affects all Redis versions with Lua scripting and is fixed in 8.2.2.

Impact

An attacker with valid credentials can corrupt memory and potentially execute arbitrary code in the context of the redis-server process. This can lead to full compromise of the Redis instance and any data or host access it holds.

Attack surface

Reachable over the network via the Redis protocol by an authenticated user who can run EVAL or EVALSHA; no user interaction is required. The CVSS vector confirms network access, low privileges, and no UI.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.82294, 99.6th percentile), indicating elevated likelihood of exploitation. A public GitHub repository referencing the CVE exists, though no exploit tags are present in the references.

What to do

  • Upgrade redis-server to version 8.2.2 or later.
  • If patching is not immediately possible, use ACLs to restrict EVAL and EVALSHA commands for all non-administrative users.
  • Disable or remove Lua scripting entirely where it is not required.
  • Restrict network access to Redis instances to trusted hosts and require strong authentication.
  • Monitor for and rotate any credentials that may have been exposed to untrusted users.

Detection

  • Audit Redis ACLs and command usage to identify accounts with EVAL or EVALSHA permissions.
  • Monitor Redis logs and slowlog for unusual or repeated Lua script executions.
  • Watch for unexpected process behavior or outbound connections from redis-server hosts.
  • Track Redis version inventory to confirm 8.2.2+ is deployed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-49844 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-0543Debian-packaged Redis Lua sandbox escape allows remote code executionA Debian-specific packaging flaw in Redis leaves the Lua interpreter's sandbox improperly restricted, allowing escape from the Lua sandbox. Because R…KEVEPSS 99%analysed9.8CVE-2025-27151Redis improper input validation vulnerabilityRedis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exi…EPSS 0.95%9.8CVE-2024-46981Redis use after free vulnerabilityRedis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the gar…EPSS 8.2%9.8CVE-2022-3734Redis untrusted search path vulnerabilityA vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Pro…EPSS 0.65%9.8CVE-2022-35951Redis integer overflow vulnerabilityRedis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `X…EPSS 3.9%8.8CVE-2025-46817Redis integer overflow vulnerabilityRedis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu…EPSS 3.8%8.8CVE-2024-31449Redis improper input validation vulnerabilityRedis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack bu…EPSS 4.5%8.8CVE-2022-24834Redis heap-based buffer overflow vulnerabilityRedis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson libr…EPSS 41%

Source: NIST National Vulnerability Database (record CVE-2025-49844), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.