CVE-2025-48367: Redis
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.
Affected products
- Redis Redis: before 6.2.19 (fixed in 6.2.19); from 7.0, before 7.2.10 (fixed in 7.2.10); from 7.4.0, before 7.4.5 (fixed in 7.4.5); from 8.0.0, before 8.0.3 (fixed in 8.0.3)
Published 2025-07-07. Last modified 2026-06-17.