logo

Understanding CVE-2025-49844: “RediShell” Critical Remote Code Execution in Redis

ID: e3945015-e482-586a-a4f7-5e59345374f7

STIX ID: report--e3945015-e482-586a-a4f7-5e59345374f7

Feed Name: Sysdig Blog

Threat Score
78/100

Date Published: 2025-10-07

Date Updated: 2026-05-01

...
...

CVE-2025-49844 (RediShell) is a critical (CVSS 10.0) use-after-free vulnerability in Redis Lua scripting that can be triggered by an authenticated user to achieve sandbox escape and remote/native code execution on the host. Redis released patches for multiple OSS/Enterprise/Stack versions on October 3, 2025; mitigations include upgrading to fixed versions, restricting EVAL/EVALSHA via ACLs, disabling Lua if unused, enforcing authentication, removing internet exposure, and running Redis as non-root. No confirmed public exploit is reported yet, but proof-of-concept work is underway, and cloud customers were auto-patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.