CVE-2025-32023
Hyperloglog out-of-bounds write from a crafted hyperloglog value -> remote code execution
- Severity
- high
- Affected product
- Redis
- Affected versions
- Redis ≥ 6.2.0, < 6.2.19
- Affected versions
- Redis ≥ 7.0.0, < 7.2.10
- Affected versions
- Redis ≥ 7.4.0, < 7.4.5
- Affected versions
- Redis ≥ 8.0.0, < 8.0.3
- Fixed in
- Redis 6.2.19 / 7.2.10 / 7.4.5 / 8.0.3
- Added to NewScan
- 2026-08-06
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Redis from its response and reports this CVE when the detected version falls inside the affected range below.
Ranges taken from the Redis security advisory (2026-08-05 review), not inferred. Redis backports per maintained branch, so each CVE is ONE ROW PER BRANCH the advisory names a fixed version for - a branch the advisory does not list gets no row rather than a guessed range, so an older patched line is never falsely flagged. GHSA-rp2m-q4j6-gr43 rates this High (CVSS 7.0) and states affected >= 2.8; the branch fixes are the ones named in the release notes.
COMPONENT VERSION RANGE
NewScan fingerprints Redis from its response and reports this CVE when the detected version falls inside the affected range below.
Ranges taken from the Redis security advisory (2026-08-05 review), not inferred. Redis backports per maintained branch, so each CVE is ONE ROW PER BRANCH the advisory names a fixed version for - a branch the advisory does not list gets no row rather than a guessed range, so an older patched line is never falsely flagged. GHSA-rp2m-q4j6-gr43 rates this High (CVSS 7.0) and states affected >= 2.8; the branch fixes are the ones named in the release notes.
COMPONENT VERSION RANGE
NewScan fingerprints Redis from its response and reports this CVE when the detected version falls inside the affected range below.
Ranges taken from the Redis security advisory (2026-08-05 review), not inferred. Redis backports per maintained branch, so each CVE is ONE ROW PER BRANCH the advisory names a fixed version for - a branch the advisory does not list gets no row rather than a guessed range, so an older patched line is never falsely flagged. GHSA-rp2m-q4j6-gr43 rates this High (CVSS 7.0) and states affected >= 2.8; the branch fixes are the ones named in the release notes.
COMPONENT VERSION RANGE
NewScan fingerprints Redis from its response and reports this CVE when the detected version falls inside the affected range below.
Ranges taken from the Redis security advisory (2026-08-05 review), not inferred. Redis backports per maintained branch, so each CVE is ONE ROW PER BRANCH the advisory names a fixed version for - a branch the advisory does not list gets no row rather than a guessed range, so an older patched line is never falsely flagged. GHSA-rp2m-q4j6-gr43 rates this High (CVSS 7.0) and states affected >= 2.8; the branch fixes are the ones named in the release notes.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →