ZDI-CAN-27195: ZDI-25-933: (Pwn2Own) Redis Lua Use-After-Free Remote Code Execution Vulnerability
Published Oct 6, 2025
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Redis. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-49844.
Affected Software
1 affected component
Redis redis
Event History
Oct 6, 2025
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-27195?
ZDI-CAN-27195 has a CVSS rating of 9.8, indicating critical severity.
2
How do I fix ZDI-CAN-27195?
To address ZDI-CAN-27195, update Redis to the latest version that includes patches for this vulnerability.
3
What does ZDI-CAN-27195 allow attackers to do?
ZDI-CAN-27195 allows remote attackers to execute arbitrary code on affected installations of Redis.
4
Is authentication required to exploit ZDI-CAN-27195?
No, no authentication is required to exploit ZDI-CAN-27195.
5
Which software is affected by ZDI-CAN-27195?
The affected software for ZDI-CAN-27195 is Redis.