Home / Companies / Redis / Blog / Post Details
Content Deep Dive

Security Advisory: CVE-2025-21605

Blog post from Redis

Post Details
Company
Date Published
Author
Quincy Castro
Word Count
349
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Redis Community and Redis have identified and remediated a security vulnerability, CVE-2025-21605, which allows an unauthenticated client to abuse the output buffer, causing a denial-of-service (DoS) attack. This vulnerability affects all versions of Redis Software and OSS/CE/Stack releases, with fixed releases available in 7.22.0-28 and above for Software, and 7.4.3 and above for OSS/CE. Exposure to this vulnerability requires a publicly exposed Redis endpoint. The community thanks researchers who identified and reported the vulnerabilities through their published process. To protect against this vulnerability, users are advised to follow best practices and upgrade their Redis to the latest release.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.