CVE Brief[verified]@DailyCVEBriefDisclosure
The tweet announces that CVE‑2025‑49844 in Redis’s Lua scripting involves a use‑after‑free leading to sandbox escape and remote code execution, noting the high CVSS score but no known exploitation or available patch.
Nishanth[verified]@Nishanth_KJDisclosure
The tweet announces CVE-2025-49844, a critical UAF flaw in Redis up to 8.2.1 that enables remote code execution via Lua scripting, without mentioning patches, exploits, or active exploitation.
Open Source Security mailing list@oss_securityPatch
Apache Kvrocks is affected by CVE‑2024‑31449 and CVE‑2025‑49844 (Redis Lua), which have been fixed but no formal advisory has yet been issued.
@pedri77@pedri77Disclosure
Redis announces a new maximum‑severity vulnerability (CVE‑2025‑49844) that may lead to remote code execution under certain conditions, with no evidence of exploitation, PoC, or available patches yet.
NerdieNews@NewsNerdieDisclosure
The post announces two new CVEs (CVE-2025-49844, CVE-2025-46817) impacting Schneider Electric Plant iT/Brewmaxx, highlighting potential privilege escalation and remote code execution in versions 9.60 and above, without any exploit code or patch information.
Diop Makhtar@pmdiop221PoC
A Medium article was published detailing a proof‑of‑concept for escaping the Redis Lua sandbox (CVE‑2025‑49844).