Critical Redis Lua Use-After-Free RCE Vulnerability Exploited
Article Content
- •CVE-2025-49844 is a critical RCE vulnerability in Redis Lua interpreter with CVSS 10.0.
- •Over 8,500 unencrypted Redis instances are vulnerable to exploitation.
- •The vulnerability can be mitigated by updating to version 8.2.2 or restricting Lua script execution.
CVE-2025-49844 is a critical use-after-free vulnerability in the Redis Lua interpreter, affecting all versions up to 8.2.1. Authenticated attackers can exploit this flaw by sending a crafted EVAL command that manipulates the garbage collector, potentially leading to remote code execution. The vulnerability has a CVSS score of 10.0, indicating its severity. Affected systems include unencrypted Redis instances, with over 8,500 identified as vulnerable as of October 2025. The issue has been patched in version 8.2.2, and users are advised to restrict Lua script execution as a workaround. The vulnerability was first publicly disclosed in 2019, with a proof of concept released shortly after. Organizations using Redis are urged to apply the patch or implement access controls to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2025-49844 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…