CVE-2025-49844Disclosure(lfprojects / redis)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch lfprojects redis systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • redis
  • valkey

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 5d ago at 1 mentions (2026-03-23); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Products
redisvalkey

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-03-23: 1Mentions · 2026-03-24: 1Mentions · 2026-04-19: 1Mentions · 2026-07-09: 1Mentions · 2026-08-31: 1Mentions · 2026-09-23: 1PoC Mentioned / Linked · 2026-03-23: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-03-24: 1Technical Details · 2026-04-19: 1Technical Details · 2026-07-09: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-23: 103-2303-2404-1907-0908-3109-23
Signal classification3 categories
Disclosure
466.7%
PoC
116.7%
Patch
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-231
PoC1
2026-03-241
Disclosure1
2026-04-191
Patch1
2026-07-091
Disclosure1
2026-08-311
Disclosure1
2026-09-231
Disclosure1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Patch

    Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory https://www.openwall.com/lists/oss-security/2026/04/16/6

    Post summary

    Apache Kvrocks is affected by CVE‑2024‑31449 and CVE‑2025‑49844 (Redis Lua), which have been fixed but no formal advisory has yet been issued.

    00030720
    4.7K followersView on X
  • CVE Brief@DailyCVEBrief
    Disclosure

    LOOK BACK — Redis shipped Lua scripting in 2012 on a frozen copy of the Lua 5.1 interpreter. CVE-2025-49844 hid a use-after-free in that ~13-year-old code: CVSS 9.9, sandbox escape to RCE. The forecast said exploits within days — 9 months on, it's quiet. https://t.co/ClW3JjZGUU

    Post summary

    The tweet announces that CVE‑2025‑49844 in Redis’s Lua scripting involves a use‑after‑free leading to sandbox escape and remote code execution, noting the high CVSS score but no known exploitation or available patch.

    1000059
    21 followersView on X
  • Nishanth@Nishanth_KJ
    Disclosure

    Redis has a critical UAF flaw (CVE-2025-49844) up to 8.2.1. The vulnerability allows remote code execution via Lua scripting. How are you isolating access to script commands? #Redis #Security #UAF #CVE

    Post summary

    The tweet announces CVE-2025-49844, a critical UAF flaw in Redis up to 8.2.1 that enables remote code execution via Lua scripting, without mentioning patches, exploits, or active exploitation.

    0000028
    64 followersView on X
  • @pedri77@pedri77
    Disclosure

    Redis has disclosed details of a maximum-severity security flaw in its in-memory database software that could result in remote code execution under certain circumstances. The vulnerability, tracked as CVE-2025-49844 (ak... https://f.mtr.cool/2bbtyupxhq

    Post summary

    Redis announces a new maximum‑severity vulnerability (CVE‑2025‑49844) that may lead to remote code execution under certain conditions, with no evidence of exploitation, PoC, or available patches yet.

    0000050
    2.1K followersView on X
  • NerdieNews@NewsNerdie
    Disclosure

    🚨 BREAKING: Schneider Electric Plant iT/Brewmaxx vulnerabilities could lead to privilege escalation and remote code execution. Versions 9.60 and above are affected. Stay alert for updates on CVE-2025-49844, CVE-2025-46817. #CyberSecurity #BreakingNews

    Post summary

    The post announces two new CVEs (CVE-2025-49844, CVE-2025-46817) impacting Schneider Electric Plant iT/Brewmaxx, highlighting potential privilege escalation and remote code execution in versions 9.60 and above, without any exploit code or patch information.

    00000192
    50 followersView on X
  • Diop Makhtar@pmdiop221
    PoC

    I just published RediShell Unmasked: Escaping the Redis Lua Sandbox (CVE-2025–49844) https://medium.com/p/redishell-unmasked-escaping-the-redis-lua-sandbox-cve-2025-49844-185509897900?source=social.tw

    Post summary

    A Medium article was published detailing a proof‑of‑concept for escaping the Redis Lua sandbox (CVE‑2025‑49844).

    0000051
    4 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsvalkey---
Appredisredis---

Explore more