CVE-2025-46817

Published Oct 3, 2025

Last updated 3 months ago

Overview

Description
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause an integer overflow and potentially lead to remote code execution The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2.
Source
security-advisories@github.com
NVD status
Analyzed
Products
redis

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security-advisories@github.com
CWE-190

Social media

Hype score
Not currently trending
  1. 🚨 BREAKING: Schneider Electric Plant iT/Brewmaxx vulnerabilities could lead to privilege escalation and remote code execution. Versions 9.60 and above are affected. Stay alert for updates on CVE-2025-49844, CVE-2025-46817. #CyberSecurity #BreakingNews

    @NewsNerdie

    24 Mar 2026

    160 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 Attention System Admins & DevOps Professionals! 🚨A critical vulnerability (CVE-2025-46817) has been found in #Valkey, the high-performance Redis fork, impacting #SUSE Linux Enterprise Server 15. Read more: 👉 https://t.co/pO6o0ThUum #Security https://t.co/imSUIyi

    @Cezar_H_Linux

    15 Jan 2026

    57 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. #AppSec #Cloud_Security 1⃣ PoC for CVE-2025-49844, CVE-2025-46817 and CVE-2025-46818 Critical Lua Engine Vulnerabilities https://t.co/pNWl2H7vmu // Three critical vulnerabilities in Redis 7.4.5 2⃣ Hunting for Bucket Traversals in Google's Client Libraries

    @ksg93rd

    11 Nov 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2025-46817 - critical 🚨 Redis < 8.2.1 lua script - Integer Overflow > Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and... 👾 https://t.co/7cbIlU0oc8 @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    11 Oct 2025

    156 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. PoC for CVE-2025-49844, CVE-2025-46817 and CVE-2025-46818 Critical Lua Engine Vulnerabilities https://t.co/FyOpCCCeTt

    @Dinosn

    7 Oct 2025

    2446 Impressions

    6 Retweets

    12 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-46817 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause… https://t.co/kkZvkL0mXr

    @CVEnew

    3 Oct 2025

    350 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations