CVE-2025-46686

EUVD-2025-22464
Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient permissions. NOTE: this is disputed by the Supplier because abuse of the commands network protocol is not a violation of the Redis Security Model.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
mitreCNA
3.5 LOW
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 19.17%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
redisredis
𝑥
≤ 8.0.3
CNA
Debian logo
Debian Releases
Debian Product
Codename
redis
bookworm
unimportant
bookworm (security)
unimportant
bullseye
unimportant
bullseye (security)
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
trixie (security)
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
redis
bionic
needed
focal
needed
jammy
needed
noble
needed
plucky
ignored
questing
ignored
resolute
needed
trusty
needed
xenial
needed