logo

RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score

ID: d1e998c3-19ce-55be-920b-e917edadd199

STIX ID: report--d1e998c3-19ce-55be-920b-e917edadd199

Feed Name: Wiz Blog

Threat Score
92/100

Date Published: 2025-10-06

Date Updated: 2026-05-01

...
...

**RediShell (CVE-2025-49844)** disclosed by Wiz Research is a critical CVSS 10.0 Remote Code Execution vulnerability in Redis that allows a post-auth attacker to escape the Lua sandbox via a Use-After-Free and execute arbitrary native code on the host; it affects Redis forks and managed services, with the report noting ~330,000 internet-exposed instances and ~60,000 unauthenticated instances, and urges immediate patching and hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.