PT-2026-37092 · Redis+2 · Redis-Server+3

·

CVE-2026-25243

·

Published

2026-05-05

·

Updated

2026-07-08

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions redis-server versions prior to 8.6.3
Description Redis is an in-memory data structure store. The RESTORE command fails to properly validate serialized values. An authenticated attacker with permissions to execute this command can provide a crafted serialized payload, triggering invalid memory access which may lead to remote code execution.
Recommendations Update to version 8.6.3. Restrict access to the RESTORE command using ACL rules as a temporary workaround.

Exploit

Fix

RCE

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:23229
ALSA-2026:25219
ALSA-2026:25925
ALSA-2026:26008
BDU:2026-06448
BIT-KEYDB-2026-25243
BIT-REDIS-2026-25243
BIT-VALKEY-2026-25243
CVE-2026-25243
GHSA-C8H9-259X-JFF4
OESA-2026-2237
OPENSUSE-SU-2026:10711-1
OPENSUSE-SU-2026:10719-1
OPENSUSE-SU-2026:20776-1
RHSA-2026:23229
RHSA-2026:25216
RHSA-2026:25219
RHSA-2026:26008
RHSA-2026:26233
RHSA-2026:27716
RHSA-2026:27787
RHSA-2026:28139
RHSA-2026:28142
RHSA-2026:29817
RHSA-2026:33427
SUSE-SU-2026:1949-1
SUSE-SU-2026:1950-1
SUSE-SU-2026:2097-1
SUSE-SU-2026:2098-1
SUSE-SU-2026:2099-1
SUSE-SU-2026:2100-1
SUSE-SU-2026:21814-1

Affected Products

Red Os
Redis
Rocky Linux
Redis-Server