Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-32xw-c2hw-m34g

Опубликовано: 27 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.2
CVSS3: 9.8

Описание

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.

EPSS

Процентиль: 37%
0.00435
Низкий

9.2 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 9.8
nvd
20 дней назад

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.

CVSS3: 9.8
debian
20 дней назад

Redis contains a use-after-free vulnerability in the 'tlsProcessPendin ...

EPSS

Процентиль: 37%
0.00435
Низкий

9.2 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-416