Patch Now: 'RediShell' Threatens Cloud Via Redis RCE
ID: 235fa421-828b-5161-b8e4-2c5b65269814
STIX ID: report--235fa421-828b-5161-b8e4-2c5b65269814
Feed Name: Dark Reading
Date Published: 2025-10-07
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
Wiz Research disclosed a critical, decade-old Redis vulnerability (CVE-2025-49844, “RediShell”) that allows post-auth attackers to send malicious Lua scripts to escape the Lua sandbox via a use-after-free and achieve arbitrary native code execution on Redis hosts. With a CVSS of 10 and an estimated 300,000 exposed instances (60,000 without authentication), the flaw poses a widespread risk to cloud environments; vendors released patches and guidance to patch, restrict network access, require authentication, disable Lua for untrusted users, and monitor for exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
