#lua-scripting

[ follow ]
#redis
fromThe Hacker News
3 days ago
Information security

13-Year Redis Flaw Exposed: CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely

Authenticated attackers can exploit a Lua-related use-after-free in Redis (CVE-2025-49844) to achieve remote code execution; apply patches and restrict Lua execution immediately.
fromTheregister
3 days ago
Information security

13-year-old level-10 bug in Redis could allow RCE

A 13-year-old Lua scripting flaw in Redis (CVE-2025-49844) lets authenticated users trigger use-after-free and potential remote code execution; patch self-managed instances immediately.
[ Load more ]