Redis Products Multiple Vulnerabilities
Release Date:
8 May 2026
7946
Views
RISK: Medium Risk
TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in Redis Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.
Impact
- Denial of Service
- Security Restriction Bypass
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- For CVE-2026-23479, CVE-2026-25243, CVE-2026-25588 and CVE-2026-25589
- All Redis Cloud deployments
- Redis Software versions up to and including 8.0.6
- All Redis OSS/CE releases
For CVE-2026-23631
- All Redis OSS releases where
replica-read-onlyis disabled
- All Redis OSS releases where
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
Source
Related Link
Related Tags
Share with
