Redis 5.0

Status EOLSupport 2018-10 – 2022-04Latest 5.0.14Vulnerabilities 34← All Redis versions
Critical 10.0 Unfixed
2025-10-03≤ 5.0.14

Redis Lua Use-After-Free may lead to remote code execution

KEV
2022-02-18< 5.0.14

High 7.5 Unfixed
2025-04-23≤ 5.0.14

Redis DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated client

High 7.5
2021-10-04< 5.0.14

Integer overflow issue with Streams in Redis

High 7.5
2021-10-04< 5.0.14

Vulnerability in handling large ziplists

High 7.5
2021-10-04< 5.0.14

Lua scripts can overflow the heap-based Lua stack in Redis

High 7.5
2021-10-04< 5.0.14

Integer overflow issue with intsets in Redis

High 7.5
2021-10-04< 5.0.14

DoS vulnerability in Redis

High 7.5
2021-10-04< 5.0.14

Integer overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platforms

High 7.5
2021-10-04< 5.0.14

Integer overflow issue with strings in Redis

High 7.0 Unfixed
2025-07-07≤ 5.0.14

Redis allows out of bounds writes in hyperloglog commands leading to RCE

High 7.0 Unfixed
2025-10-03≤ 5.0.14

Lua library commands may lead to integer overflow and potential RCE

High 7.0 Unfixed
2023-07-13≤ 5.0.14

Heap overflow issue with the Lua cjson library used by Redis

Medium 6.3 Unfixed
2025-10-03≤ 5.0.14

Redis is vulnerable to DoS via specially crafted LUA scripts

Medium 6.0 Unfixed
2025-10-03≤ 5.0.14

Redis: Authenticated users can execute LUA scripts as a different user

Medium 5.5 Unfixed
2023-01-20≤ 5.0.14

Integer overflow in certain command arguments can drive Redis to OOM panic

Medium 5.5 Unfixed
2023-03-01≤ 5.0.14

Redis string pattern matching can be abused to achieve Denial of Service

Medium 5.5 Unfixed
2023-03-02≤ 5.0.14

Integer Overflow in several Redis commands can lead to denial of service.

Medium 5.5 Unfixed
2023-04-18≤ 5.0.14

`HINCRBYFLOAT` can be used to crash a redis-server process

Medium 5.5 Unfixed
2024-10-07≤ 5.0.14

Denial-of-service due to unbounded pattern matching in Redis

Medium 5.3
2021-10-04< 5.0.14

Vulnerability in Lua Debugger in Redis

Low 3.9 Unfixed
2022-04-27≤ 5.0.14

Lua scripts can be manipulated to overcome ACL rules in Redis

Low 3.6 Unfixed
2023-10-18≤ 5.0.14

Redis Unix-domain socket may have be exposed with the wrong permissions for a short time window.

Low 3.3 Unfixed
2022-04-27≤ 5.0.14

A Malformed Lua script can crash Redis

N/A
2021-03-31< 5.0.10

N/A
2016-04-13< 5.0.8

N/A
2018-06-17< 5.0.0

N/A
2018-06-16< 5.0

N/A
2019-07-11< 5.0.4

N/A
2019-07-11< 5.0.4

N/A
2020-06-15< 5.0.9

N/A Unfixed
2021-09-20= 5.0.7

N/A
2021-02-26< 5.0.11

N/A
2021-07-21< 5.0.13