Skip to content

Comment on Redis CVE-2025-49844: Use-After-Free may lead to remote code executionparent

Comments

I’d imagine recent uptick in using services like Upstash may make it harder for people to know if they are vulnerable or not. Is this mitigated by disabling Lua script execution?

Upstash wouldn’t be vulnerable - Upstash doesn’t run upstream redis, it’s a protocol-compatible proprietary implementation.

I would guess it is.

Also:

Exploitation of this vulnerability requires an attacker to first gain authenticated access to your Redis instance.
AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.