CVE-2024-31449Patch(redis / redis)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redis redis systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This problem has been fixed in Redis versions 6.2.16, 7.2.6, and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • redis

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
redis

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-19: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-19: 104-19
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Open Source Security mailing list@oss_security
    Patch

    Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory https://www.openwall.com/lists/oss-security/2026/04/16/6

    Post summary

    Apache Kvrocks was affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua) but both issues have been fixed, though a formal vendor advisory is still pending.

    00030720
    4.7K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appredisredis---
Appredisredis7.4.0--
Appredisredis7.4.0--
Appredisredis7.4.0--

Explore more