Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-46817


Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause an integer overflow and potentially lead to remote code execution The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2.


Published

2025-10-03T18:15:35.527

Last Modified

2025-10-08T15:17:49.867

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.0 (HIGH)

Weaknesses
  • Type: Primary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redis redis < 8.2.2 Yes

References