← All CVEs NewScan detects
high

CVE-2024-51737

RediSearch integer overflow via crafted FT.SEARCH/FT.AGGREGATE LIMIT or KNN arguments -> heap overflow, potential remote code execution

Severity
high
Affected product
RediSearch
Affected versions
RediSearch ≥ 2.0.0, < 2.6.24
Affected versions
RediSearch ≥ 2.8.0, < 2.8.21
Affected versions
RediSearch ≥ 2.10.0, < 2.10.10
Fixed in
RediSearch 2.6.24 / 2.8.21 / 2.10.10
Added to NewScan
2026-08-06
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints RediSearch from its response and reports this CVE when the detected version falls inside the affected range below.

Module version comes from MODULE LIST on an unauthenticated instance (redis_recon decodes Redis' packed integer, e.g. 21010 -> 2.10.10). Ranges from the Redis module advisories.

COMPONENT VERSION RANGE

NewScan fingerprints RediSearch from its response and reports this CVE when the detected version falls inside the affected range below.

Module version comes from MODULE LIST on an unauthenticated instance (redis_recon decodes Redis' packed integer, e.g. 21010 -> 2.10.10). Ranges from the Redis module advisories.

COMPONENT VERSION RANGE

NewScan fingerprints RediSearch from its response and reports this CVE when the detected version falls inside the affected range below.

Module version comes from MODULE LIST on an unauthenticated instance (redis_recon decodes Redis' packed integer, e.g. 21010 -> 2.10.10). Ranges from the Redis module advisories.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →