Redis has closed new RCE chains: what you need to know now

Colleagues, I’d like to flag a cybersecurity update: researchers have identified two new chains in Redis that may lead to RCE.
They demonstrated exploits for RESTORE scenarios in Redis Streams and in the RedisBloom/TDigest combination.
Redis has released seven updates and fixed the issues across branches 6.2, 7.2, 7.4, 8.2, 8.4, 8.6 and 8.8.
In practical terms, “we updated in May” no longer guarantees protection — it is essential to check the exact branch in use.
Why this matters: until the fix is in place, I would restrict RESTORE, remove unnecessary Redis access, and make sure the network is not exposed to untrusted nodes.
Have you already checked Redis versions in your environments?
#cybersecurity #Redis #Vulnerability #RCE


Latest comments
No comments yet.