Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2.3) | 0.28% | — | Langchain RedisAI | 6/10/2026 | 6/10/2026 | LangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected RediSearch syntax to alter or broaden the generated search query. When an… | |
| Pendiente de análisis | Alta (7.5) | 0.39% | — | HiredisAI | 24/9/2026 | 24/9/2026 | hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser. | |
| Aplazada | Alta (8.7) | 0.39% | — | Redis-parserAI | 24/9/2026 | 24/9/2026 | redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a crafted RESP header with a length above 2^32-1 to crash the… | |
| Aplazada | Baja (3.7) | 0.41% | — | Thinkst OpencanaryAIRedisAI | 21/9/2026 | 22/9/2026 | Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause unconstrained memory usage. | |
| Pendiente de análisis | Alta (7.5) | 0.34% | — | NettyAIRedisAI | 18/9/2026 | 25/9/2026 | A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to eagerly preallocate a large amount of heap memory, leading to heap memory exhaustion and a Denial… | |
| Pendiente de análisis | Alta (8.7) | 0.68% | — | Redis-parserAI | 17/9/2026 | 28/9/2026 | redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack,… | |
| Pendiente de análisis | Alta (7.1) | 0.40% | — | RedisAI | 17/9/2026 | 22/9/2026 | A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's… | |
| Aplazada | Media (5.1) | 0.53% | — | MispAIRedisAI | 15/9/2026 | 16/9/2026 | Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentication activity. However, User->setupRedis() returns false when Redis cannot be reached. The vulnerable _shouldLog() logic only returned true… | |
| Aplazada | Crítica (9.8) | 0.73% | — | PredisAI | 1/9/2026 | 9/9/2026 | Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode("\r\n") instead of… | |
| Pendiente de análisis | Alta (7.5) | 0.48% | — | RedisAI | 27/8/2026 | 31/8/2026 | Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. | |
| Aplazada | Media (6.9) | 0.45% | — | RansomlookAIRedisAI | 24/8/2026 | 26/8/2026 | Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralization of user-controlled input before it is incorporated into Redis SCAN MATCH patterns. The /api/health/<name> endpoint attempted to resolve the supplied name to a known group or market, but when resolution failed it fell… | |
| Pendiente de análisis | Alta (7.5) | 0.87% | — | RedisAI | 25/7/2026 | 9/9/2026 | Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue… | |
| Aplazada | Crítica (10) | 0.48% | — | Apache KvrocksAIRedis LUAAICjsonAI | 25/6/2026 | 25/6/2026 | Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. | |
| Analizada | Media (6.4) | 0.27% | — | Broadcom Spring Data KeyvalueBroadcom Spring Data Redis | 10/6/2026 | 23/7/2026 | A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. Affected versions: Spring Data KeyValue / Spring Data Redis 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through… | |
| Pendiente de análisis | Alta (8.7) | 0.32% | — | RedisAI | 5/6/2026 | 7/10/2026 | An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication, including authentication, occurs over… | |
| Analizada | Alta (7.7) | 0.81% | 💥 PoC | Redisbloom | 5/5/2026 | 25/7/2026 | RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisBloom module loaded… | |
| Analizada | Alta (7.7) | 0.81% | — | Redistimeseries | 5/5/2026 | 25/7/2026 | RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisTimeSeries module loaded can… | |
| Modificada | Alta (7.7) | 3.7% | 💥 PoC | Redis | 5/5/2026 | 25/7/2026 | Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code… | |
| Modificada | Media (6.1) | 2.8% | 💥 PoC | Redis | 5/5/2026 | 25/7/2026 | Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A… | |
| Modificada | Alta (7.7) | 1.5% | 💥 PoC | Redis | 5/5/2026 | 25/7/2026 | Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free… | |
| Aplazada | Media (6.5) | 0.49% | — | Langchain Langgraph-checkpoint-redisAI | 20/2/2026 | 17/6/2026 | @langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package's filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating… | |
| Analizada | Alta (7.7) | 6.8% | 💥 PoC | Redis | 4/11/2025 | 17/6/2026 | Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's and trigger a stack buffer overflow, which may potentially lead to remote code execution. This issue is fixed in version 8.2.3. To workaround this issue without patching… | |
| Analizada | Alta (8.7) | 0.66% | — | Microsoft Azure Cache FOR RedisMicrosoft Azure Managed Redis | 9/10/2025 | 17/6/2026 | Redis Enterprise Elevation of Privilege Vulnerability | |
| Modificada | Crítica (9.9) | 82% | 💥 Exploit | RedisLfprojects Valkey | 3/10/2025 | 17/6/2026 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem exists in all versions of Redis with Lua… | |
| Analizada | Alta (7.1) | 1.1% | 💥 Exploit | Redis | 3/10/2025 | 17/6/2026 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LUA script to read out-of-bound data or crash the server and subsequent denial of service. The problem exists in all versions of Redis with Lua scripting. This issue is… |