CVE-2025-32023PoC(redis / redis)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a stack/heap out of bounds write on hyperloglog operations, potentially leading to remote code execution. The bug likely affects all Redis versions with hyperloglog operations implemented. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19. An additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing hyperloglog operations. This can be done using ACL to restrict HLL commands.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-680

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • redis

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
redis

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-11: 1PoC Mentioned / Linked · 2026-02-11: 1Technical Details · 2026-02-11: 102-11
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Red Secure Tech Ltd.@redsecuretech
    PoC

    CVE-2025-32023 PoC exploits malformed HyperLogLog in Redis 8.0.x causing integer overflow & heap corruption during PFCOUNT. https://redsecuretech.co.uk/blog/post/redis-hll-overflow-rce-in-8-0-0-8-0-2/909 #Cybersecurity #CVE #Redis #RCE #HyperLogLog #RedisSecurity #ExploitPoC #ThreatIntel #Vulnerability #PatchNow https://t.co/4UsA9oisbR

    Post summary

    The post announces a PoC for CVE‑2025‑32023, detailing an integer overflow and heap corruption in Redis 8.0.x via malformed HyperLogLog during PFCOUNT, but does not mention active exploitation or a patch.

    0101070
    41 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredisredis---

Explore more