Skip to content
Threat Feed

Vendor

Redis

9 briefs RSS
low advisory

Resource Exhaustion in RedisArrayAggregator

A vulnerability in RedisArrayAggregator allows remote attackers to trigger memory exhaustion via a crafted RESP payload that forces eager allocation of array capacity.

RedisArrayAggregator denial-of-service memory-exhaustion redis
1c
low advisory

Denial of Service Vulnerability in redis-parser via RESP Recursion

The redis-parser library up to version 3.0.0 is vulnerable to a denial of service attack where crafted RESP byte streams trigger unbounded recursion, exhausting the V8 call stack and crashing the host Node.js process.

redis-parser denial-of-service vulnerability supply-chain
1c
high advisory

Out-of-Bounds Read Vulnerability in Redis Cluster Bus

A vulnerability in the Redis cluster bus packet parser allows remote attackers to trigger an out-of-bounds read via crafted PING, PONG, or MEET packets, resulting in potential information disclosure or denial of service.

Redis vulnerability memory-safety denial-of-service
1c
medium advisory

Redis Vulnerability Enables Denial of Service and Information Disclosure

A vulnerability in Redis allows an attacker located in an adjacent network to trigger a Denial of Service condition and perform unauthorized information disclosure.

Redis
1t 1c
high advisory

Suspicious Redis Server Process Execution

Detection of unauthorized system shell and utility execution originating from Redis server processes indicative of post-exploitation activity or sandbox escapes like CVE-2022-0543.

redis-server +1 redis linux post-exploitation cve-2022-0543
1r 1t 1c
medium advisory

Redis Authenticated Remote Code Execution Vulnerability

A vulnerability in Redis allows a remote, authenticated attacker to achieve arbitrary code execution on the target server.

Redis vulnerability rce database
1t
critical advisory

Multiple Vulnerabilities in Redis Allow Remote Code Execution

Multiple vulnerabilities in Redis could allow an attacker to execute arbitrary code remotely, potentially leading to complete system compromise.

Redis rce vulnerability
2r 1t 3c
high advisory

Open WebUI Cross-Instance Cache Poisoning Vulnerability

Open WebUI versions up to 0.8.12 are vulnerable to cross-instance cache poisoning when multiple instances share a Redis backend, allowing an attacker with admin access on one instance to overwrite cache values used by other instances, leading to data exfiltration and prompt injection attacks.

open-webui +1 cache-poisoning redis vulnerability
2r 2t
critical advisory

Redis Vulnerabilities Allow Local Code Execution

A local attacker can exploit multiple unspecified vulnerabilities in Redis to achieve arbitrary code execution on the host system.

Redis code-execution local-privilege-escalation
2r 1t