Back to Database
Status published
High
CVE-2025-48367
Redis DoS Vulnerability due to bad connection error handling
Vulnerability Description
Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-48367
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/redis/redis/security/advisories/GHSA-4q32-c38c-pwgq
- https://github.com/redis/redis/commit/bde62951accfc4bb0a516276fd0b4b307e140ce2
- https://github.com/redis/redis/releases/tag/6.2.19
- https://github.com/redis/redis/releases/tag/7.2.10
- https://github.com/redis/redis/releases/tag/7.4.5
- https://github.com/redis/redis/releases/tag/8.0.3
More from redis
View All →CVE-2025-62507
Redis: Bug in XACKDEL may lead to stack overflow and potential RCE
High
7.7
CVE-2025-49844
Redis Lua Use-After-Free may lead to remote code execution
Critical
10
CVE-2025-46819
Redis is vulnerable to DoS via specially crafted LUA scripts
Medium
6.3
CVE-2025-46818
Redis: Authenticated users can execute LUA scripts as a different user
Medium
6
CVE-2025-46817
Lua library commands may lead to integer overflow and potential RCE
High
7
Affected Vendor
redis
View all reports →Affected Software
redis
Vulnerable Versions:
>= 8.0.0, < 8.0.3, >= 7.4-rc1, < 7.4.5, >= 7.0.0, < 7.2.10, < 6.2.19
Timeline
Official Publish:
July 7th, 2025
Last Modified:
July 7th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H