🔐 CVE Alert

CVE-2026-92925

UNKNOWN 0.0

Out-of-Bounds Read in Cluster Bus

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding and total length but never checked that string-carrying extensions are properly null-terminated, allowing a crafted packet to trigger out-of-bounds reads when the payload is later consumed as a C string. This vulnerability can potentially lead to loss of confidentiality or remote denial of service. Redis Software / Redis Enterprise are not affected by this issue.

CWE CWE-125
Vendor redis
Product redis open source
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for redis redis open source

Be the first to know when new unknown vulnerabilities affecting redis redis open source are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Redis / Redis Open Source
7.0.0 ≤ 8.8.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/redis/redis/commit/37894faeea11e2db28b9fc2af378a762d2c36523 github.com: https://github.com/redis/redis/pull/15263 github.com: https://github.com/redis/redis/releases/tag/8.10.0