CVE-2025-46686: Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient permissions. NOTE: this is disputed by the Supplier because abuse of the commands network protocol is not a violation of the Redis Security Model.
CSIRTS triage
- What
- An authenticated user can exhaust server memory by sending multi-bulk commands with many bulks, as the server allocates memory for all command arguments even when the command is skipped due to insufficient permissions.
- Who is affected
- Redis deployments 8.0.3 and earlier with untrusted authenticated users.
- Urgency
- Low severity (CVSS 3.5) and not exploited; only affects authenticated attackers and does not grant unauthorized access.
- Action
- Upgrade to Redis version after 8.0.3 or restrict authentication to trusted users only.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Redis
Get an email when a new Redis advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-46686
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-466860.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-46686 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Redis
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-63404: Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedde…nvd · 2026-08-25
- unknownCVE-2026-78378: Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutra…nvd · 2026-08-24
- high[NEW] [high] Redis: Multiple vulnerabilitiescert-bund · 2026-08-24
- medium[NEW] [medium] Redis: Vulnerability enables code executioncert-bund · 2026-08-19
- criticalCVE-2026-75854: ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wi…nvd · 2026-08-18
- mediumGHSA-j6gc-4893-qwmp: New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypassghsa · 2026-08-17
More from Microsoft Security Response Center
- lowCVE-2026-14673: PostgreSQL amcheck does not clear untrusted search path2026-08-11
- criticalCVE-2026-69836: Microsoft Entra ID Remote Code Execution Vulnerability2026-08-11
- mediumCVE-2026-53792: rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block2026-08-11
- highCVE-2026-70347: Windows Installer Elevation of Privilege Vulnerability2026-08-11
- highCVE-2026-64909: Microsoft Office Remote Code Execution Vulnerability2026-08-11