CVE-2025-49112: Valkey

Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.

setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.

Affected products

  • Valkey Valkey: up to and including 8.1.1

Published 2025-06-02. Last modified 2026-06-17.