logo

Critical Redis Lua Use-After-Free RCE Vulnerability Exploited

ID: 4f6f1896-4395-5ff7-8592-c73232a1cc2d

STIX ID: report--4f6f1896-4395-5ff7-8592-c73232a1cc2d

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-28

Date Updated: 2026-07-02

...
...

CVE-2025-49844 is a critical (CVSS 10.0) use-after-free vulnerability in the Redis Lua interpreter allowing authenticated attackers to achieve remote code execution via crafted EVAL commands; it affects Redis versions up to 8.2.1, with over 8,500 unencrypted instances identified as vulnerable, and has been patched in 8.2.2—apply the update or restrict Lua script execution to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.