CVE-2026-92925
Out-of-Bounds Read in Cluster Bus
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding and total length but never checked that string-carrying extensions are properly null-terminated, allowing a crafted packet to trigger out-of-bounds reads when the payload is later consumed as a C string. This vulnerability can potentially lead to loss of confidentiality or remote denial of service. Redis Software / Redis Enterprise are not affected by this issue.
| CWE | CWE-125 |
| Vendor | redis |
| Product | redis open source |
| Ecosystems | |
| Industries | Technology |
| Published | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for redis redis open source
Be the first to know when new unknown vulnerabilities affecting redis redis open source are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Redis / Redis Open Source
7.0.0 ≤ 8.8.1