<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:09:34.236837+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:11401</id>
    <title>ALSA-2025:11401 — Important: valkey security update</title>
    <updated>2026-10-02T20:09:34.360186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: valkey, AlmaLinux:10: valkey-devel</p>
<p>Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also.</p>
<p>Security Fix(es):</p>
<p>* redis: Redis Stack Buffer Overflow (CVE-2025-27151)
  * redis: Redis Unauthenticated Denial of Service (CVE-2025-48367)
  * redis: Redis Hyperloglog Out-of-Bounds Write Vulnerability (CVE-2025-32023)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:11401"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-09081</id>
    <title>bdu:2025-09081</title>
    <updated>2026-10-02T20:09:34.360256+00:00</updated>
    <content>bdu:2025-09081</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-09081"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-48367</id>
    <title>BELL-CVE-2025-48367</title>
    <updated>2026-10-02T20:09:34.360274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: redis, Alpaquita:25: redis, Alpaquita:stream: redis</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-48367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keydb-2025-48367</id>
    <title>BIT-keydb-2025-48367 — Redis DoS Vulnerability due to bad connection error handling</title>
    <updated>2026-10-02T20:09:34.360295+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keydb</p>
<p>Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keydb-2025-48367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125</id>
    <title>certfr-2026-avi-1125 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T20:09:34.360315+00:00</updated>
    <content>certfr-2026-avi-1125</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-16525</id>
    <title>cnvd-2025-16525</title>
    <updated>2026-10-02T20:09:34.360330+00:00</updated>
    <content>cnvd-2025-16525</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-16525"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-246474</id>
    <title>EUVD-2026-246474</title>
    <updated>2026-10-02T20:09:34.360341+00:00</updated>
    <content>EUVD-2026-246474</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-246474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48367</id>
    <title>fkie_cve-2025-48367</title>
    <updated>2026-10-02T20:09:34.360351+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-48367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-48367</id>
    <title>msrc_CVE-2025-48367 — Redis DoS Vulnerability due to bad connection error handling</title>
    <updated>2026-10-02T20:09:34.360371+00:00</updated>
    <content>msrc_CVE-2025-48367</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-48367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1850</id>
    <title>OESA-2025-1850 — redis security update</title>
    <updated>2026-10-02T20:09:34.360386+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP2: redis, openEuler:20.03-LTS-SP4: redis, openEuler:22.03-LTS-SP3: redis, openEuler:22.03-LTS-SP4: redis, openEuler:24.03-LTS: redis, openEuler:24.03-LTS-SP1: redis</p>
<p>Redis is an advanced key-value store. It is often referred to as a dattructure server since keys can contain strings, hashes ,lists, sets anorted sets.

Security Fix(es):</p>
<p>Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a stack/heap out of bounds write on hyperloglog operations, potentially leading to remote code execution. The bug likely affects all Redis versions with hyperloglog operations implemented. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19. An additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing hyperloglog operations. This can be done using ACL to restrict HLL commands.(CVE-2025-32023)</p>
<p>Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.(CVE-2025-48367)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1850"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15318-1</id>
    <title>openSUSE-SU-2025:15318-1 — redis-8.0.3-1.1 on GA media</title>
    <updated>2026-10-02T20:09:34.360421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>redis-8.0.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15318-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:12468</id>
    <title>RHSA-2025:12468 — Red Hat Security Advisory: redis security update</title>
    <updated>2026-10-02T20:09:34.360437+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>redis: Redis Hyperloglog Out-of-Bounds Write Vulnerability redis: Redis Unauthenticated Denial of Service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:12468"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02579-1</id>
    <title>SUSE-SU-2025:02579-1 — Security update for redis</title>
    <updated>2026-10-02T20:09:34.360455+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for redis</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02579-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48367</id>
    <title>UBUNTU-CVE-2025-48367</title>
    <updated>2026-10-02T20:09:34.360468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: redis, Ubuntu:Pro:16.04:LTS: redis, Ubuntu:Pro:18.04:LTS: redis, Ubuntu:Pro:20.04:LTS: redis, Ubuntu:Pro:22.04:LTS: redis, Ubuntu:24.04:LTS: redis, Ubuntu:24.04:LTS: valkey, Ubuntu:25.10: redict, Ubuntu:25.10: redis, Ubuntu:26.04:LTS: redict and 1 more</p>
<p>Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1463</id>
    <title>WID-SEC-W-2025-1463 — Redis: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:09:34.360499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Redis ausnutzen, um beliebigen Programmcode auszuführen, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1463"/>
  </entry>
</feed>
