CVE-2026-88382: High severity Redis Hiredis vulnerability
Published Sep 24, 2026
·Updated
hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser.
Affected Software
1 affected component
Redis Hiredis>1.5.0
Event History
Sep 24, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
How can I scope potentially affected Hiredis source builds?
The available information identifies commit 29ea279 as containing the issue and places it after v1.5.0. It does not provide affected release ranges or a fixed commit or release.
2
Does the available information provide a workaround when an update cannot be applied?
No workaround or configuration-based mitigation is provided in the available information.