CVE-2025-62507HIGH 8.8EPSS p92.7%

CVE-2025-62507CVE-2025-62507

Description

Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's and trigger a stack buffer overflow, which may potentially lead to remote code execution. This issue is fixed in version 8.2.3. To workaround this issue without patching the redis-server executable is to prevent users from executing XACKDEL operation. This can be done using ACL to restrict XACKDEL command.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS6.29% probability of exploitation · percentile 92.7% · 2026-06-18T12:00:27Z
Published2025-11-04
Last modified2025-12-08

Underlying weaknesses· 3

CWE-20CWE-121CWE-787

References

  1. https://github.com/redis/redis/commit/5f83972188f6e5b1d6f1940218c650a9cbdf7741
  2. https://github.com/redis/redis/releases/tag/8.2.3
  3. https://github.com/redis/redis/security/advisories/GHSA-jhjx-x4cf-4vm8

3

TypeTargetConfidenceTier
WeaknessStack-based Buffer Overflowcwe-1210%live
WeaknessImproper Input Validationcwe-200%live
WeaknessOut-of-bounds Writecwe-7870%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-49844
CVE
CVE-2025-46817
CVE
CVE-2026-25243
CVE
CVE-2025-27151
CVE
CVE-2026-23479
CVE
CVE-2026-23631
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.