Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Redis Critical Remote Execution Vulnerability: CVE‑2025‑49844 (redis.io)
1 point by sciencejerk 3 months ago | hide | past | favorite | 3 comments


A 13‑year Redis flaw (CVE‑2025‑49844) allows attackers to escape Lua sandbox and run code on hosts, if they are authenticated and Lua Script uploads are permitted.

Fixed releases: 7.22.2-12 and above, 7.8.6-207 and above, 7.4.6-272 and above, 7.2.4-138 and above, 6.4.2-131 and above

Exploit appears to be available, so patch quickly! https://redrays.io/blog/poc-for-cve-2025-49844-cve-2025-4681...



Apologies, missed this previous discussion




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: