Back to Database
Status published
Medium
CVE-2024-51741
Redis allows denial-of-service due to malformed ACL selectors
Vulnerability Description
Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-51741
Credits & Attribution
No credits recorded in the NVD database.
More from redis
View All →CVE-2025-62507
Redis: Bug in XACKDEL may lead to stack overflow and potential RCE
High
7.7
CVE-2025-49844
Redis Lua Use-After-Free may lead to remote code execution
Critical
10
CVE-2025-48367
Redis DoS Vulnerability due to bad connection error handling
High
7.5
CVE-2025-46819
Redis is vulnerable to DoS via specially crafted LUA scripts
Medium
6.3
CVE-2025-46818
Redis: Authenticated users can execute LUA scripts as a different user
Medium
6
Affected Vendor
redis
View all reports →Affected Software
redis
Vulnerable Versions:
>= 7.0.0, < 7.2.7, >= 7.4.0, < 7.4.2
Timeline
Official Publish:
January 6th, 2025
Last Modified:
January 6th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H