HIGH🇵🇱 Wersja polska

CVE-2025-67733

CVSS 8.5v3.1pub. 2026-02-23upd. 2026-06-30

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
  • Lfprojects Valkey

    APP
    Lfprojects
    < 7.2.128.0.0 – 8.0.7 (excl.)8.1.0 – 8.1.6 (excl.)9.0.0 – 9.0.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-49844CRITICAL9.9PL ✓same product

Redis/Valkey: RCE przez use-after-free w skryptach Lua

CVE-2026-21863HIGH7.5same product

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious act...

CVE-2026-27623HIGH7.5same product

Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious ...

CVE-2025-21605HIGH7.5same product

Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7....

CVE-2026-64849CRITICAL9.3⚠ KEVsame vendor

MLflow is an open source AI engineering platform for agents, large language models, and machine learning model...