CVE-2025-67733Patch(lfprojects / valkey)

LOWCVSS 7.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch lfprojects valkey systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-170

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • valkey

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 11 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 8d ago at 4 mentions (2026-02-23); latest day: 1
  • 12 total mentions across 9 days

Affected systems

Vendors
Products
valkey

Deep dive

Activity timeline12 mentions / 9d
01234Mentions · 2026-02-23: 4Mentions · 2026-02-24: 1Mentions · 2026-02-25: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-05: 1Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-05-18: 1PoC Mentioned / Linked · 2026-03-05: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-05-18: 1Technical Details · 2026-02-23: 4Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 102-2302-2402-2502-2702-2803-0503-1203-1305-18
Signal classification3 categories
Patch
650.0%
Disclosure
541.7%
General
18.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-234
Disclosure3Patch1
2026-02-241
Disclosure1
2026-02-251
Patch1
2026-02-271
General1
2026-02-281
Disclosure1
2026-03-051
Patch1
2026-03-121
Patch1
2026-03-131
Patch1
2026-05-181
Patch1
Full discourse12 posts
  • cPanel@cPanel
    Patch

    EasyApache 4 v25.49 is now available: • Valkey 7.2 → 7.2.12 • Fix for CVE-2026-21863 (remote DoS via malformed cluster bus message) • Fix for CVE-2025-67733 (RESP protocol injection via Lua error_reply) Full change log → https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ #EasyApache #cPanelUpdates https://t.co/qsBFfRMGJR

    Post summary

    EasyApache 4 v25.49 releases patches for CVE-2026-21863 (remote DoS) and CVE-2025-67733 (RESP protocol injection), addressing the specified vulnerabilities.

    11020541
    28.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Redis has two critical CVEs (CVE-2025-67733 & CVE-2026-21863) on Debian. Here is your practical guide: check your version, apply the fix, or mitigate with ACLs and iptables. Read more -> http://tinyurl.com/3kzpbaj7 #Debiar #Security https://t.co/mjmharjgTL

    Post summary

    The note informs about two critical Redis CVEs on Debian and recommends checking versions, applying available patches, or using ACL/iptables mitigations, with no evidence of PoC, active exploitation, or false positives.

    100001.3K
    1.5K followersView on X
  • cPanel@cPanel
    Patch

    EasyApache 4 v25.49 is now available: • Valkey 7.2 → 7.2.12 • Fix for CVE-2026-21863 (remote DoS via malformed cluster bus message) • Fix for CVE-2025-67733 (RESP protocol injection via Lua error_reply) Full change log → https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ #EasyApache #cPanelUpdates https://t.co/KvZANzBtvz

    Post summary

    EasyApache 4 v25.49 addresses CVE‑2026‑21863 and CVE‑2025‑67733 with new Valkey updates, including brief technical details but no exploitation evidence or PoC.

    00010343
    28.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-67733 Lua Script Injection Vulnerability in Valkey Versions Prior to 9.0.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-67733

    Post summary

    A Lua script injection vulnerability (CVE-2025-67733) affecting Valkey versions before 9.0.2 has been disclosed, with no PoC, exploit, or patch details provided.

    0001082
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-67733: HIGH] Valkey database had a cyber security vulnerability allowing users to inject info into responses, risking data integrity. Update to versions 9.0.2, 8.1.6, 8.0.7, 7.2.12 to fix it.#cve,CVE-2025-67733,#cybersecurity https://cvefind.com/CVE-2025-67733

    Post summary

    Valkey database CVE-2025-67733 permits response injection, compromising data integrity; the advisory lists specific patched versions to mitigate the issue.

    0001056
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2025-67733** pertains to a security flaw in **Valkey**, a distributed key-value database system. The vulnerability arises from improper handling of scripting commands, specifically Lua scripts, within the application. Prior to the fixed versions, malicious users could exploit this flaw to inject arbitrary data into the response stream by leveraging scripting commands. This could lead to data corruption or tampering, affecting data integrity and trustworthiness of responses sent to clients. #Cybersecurity #CVE #HighSeverity #SecurityAlert #DDoS https://cvetodo.com/cve/CVE-2025-67733

    Post summary

    The post announces CVE‑2025‑67733, describing a Lua script handling flaw in Valkey that permits data injection and corruption, but it does not mention patches, exploits, or active attacks.

    0001042
    20 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-67733 - High Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response st... https://www.thehackerwire.com/vulnerability/CVE-2025-67733/ https://t.co/9rzjsoxdOD

    Post summary

    Valkey database versions prior to 9.0.2, 8.1.6, 8.0.7, and 7.2.12 are vulnerable to scripting command injection that allows arbitrary information injection into responses; no PoC, exploit, or patch details are provided.

    0001054
    113 followersView on X
  • ThreatCluster@threatcluster
    Patch

    Critical DoS flaws in Valkey affect Fedora 42-43. CVE-2026-21863 and CVE-2025-67733 (PoC public) fixed in recent updates. Fedora users should patch immediately. #infosec https://threatcluster.io/cluster/critical-dos-vulnerabilities-in-valkey-affect-fedora-42-and--1ab0805c

    Post summary

    Two critical DoS CVEs in Valkey affecting Fedora 42‑43 have public PoCs and have been fixed in recent updates, urging users to patch immediately.

    00000106
    91 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-67733 (CVSS:8.5, HIGH) is Analyzed. Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use ..https://nvd.nist.gov/vuln/detail/CVE-2025-67733 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2025‑67733 as a high‑severity vulnerability in Valkey, detailing version impact and CVSS score, but provides no PoC, exploit, or patch information.

    0000078
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2025-67733 (CVSS:8.5, HIGH) is Analyzed. Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use ..https://nvd.nist.gov/vuln/detail/CVE-2025-67733 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet references CVE‑2025‑67733, noting its CVSS score and affected Valkey versions, and provides a link to the NVD entry, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000017
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Valkey` is affected by a RESP Protocol Injection vulnerability (CVE-2025-67733) via Lua error replies. This can lead to data manipulation. Update available. #Valkey #Lua #infosec https://www.pulsepatch.io/posts/cve-2025-67733-valkey-resp-protocol-injection

    Post summary

    Valkey is vulnerable to a RESP protocol injection via Lua error replies (CVE-2025-67733) that can lead to data manipulation; an update is available.

    0000031
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-67733 Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary informa… https://www.cve.org/CVERecord?id=CVE-2025-67733

    Post summary

    CVE‑2025‑67733 enables malicious users to inject arbitrary data via scripting commands in Valkey versions before 9.0.2, 8.1.6, 8.0.7, and 7.2.12.

    00000110
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsvalkey---

Explore more