Critical Redis Lua Use-After-Free RCE Vulnerability Exploited
ID: 4f6f1896-4395-5ff7-8592-c73232a1cc2d
STIX ID: report--4f6f1896-4395-5ff7-8592-c73232a1cc2d
Feed Name: ThreatCluster
Threat Score
CVE-2025-49844 is a critical (CVSS 10.0) use-after-free vulnerability in the Redis Lua interpreter allowing authenticated attackers to achieve remote code execution via crafted EVAL commands; it affects Redis versions up to 8.2.1, with over 8,500 unencrypted instances identified as vulnerable, and has been patched in 8.2.2—apply the update or restrict Lua script execution to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
