<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Redis on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/redis/</link><description>Recent content in Redis on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 03 Jun 2026 16:40:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/redis/index.xml" rel="self" type="application/rss+xml"/><item><title>Redis RCE Flaw CVE-2026-23479: 2-Year Bug Patched</title><link>https://zxcloudsecurity.co.uk/posts/redis-rce-vulnerability-cve-2026-23479-use-after-free-patched/</link><pubDate>Wed, 03 Jun 2026 16:40:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/redis-rce-vulnerability-cve-2026-23479-use-after-free-patched/</guid><description>Redis patches CVE-2026-23479, a use-after-free RCE flaw active since v7.2.0. Authenticated attackers could execute OS commands on the host. Patch now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html">The Hacker News</a></p>
<hr>
<p>A critical remote code execution vulnerability (CVE-2026-23479) in Redis, introduced in version 7.2.0 over two years ago, has been patched following discovery by an autonomous AI-powered bug-hunting tool. The flaw is a use-after-free bug in Redis&rsquo;s blocking-client handling code, allowing any authenticated user to execute arbitrary operating system commands on the host server. This is significant because Redis is widely deployed across cloud environments as a caching and data store layer, meaning exposure could lead to full host compromise.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Prioritise patching all Redis instances to the May 5 fixed release immediately, paying particular attention to managed Redis services (AWS ElastiCache, Azure Cache for Redis, GCP Memorystore) and self-hosted deployments — check with your vendors for patch availability. In the interim, enforce network segmentation and strict authentication controls to limit which services and users can reach Redis endpoints, reducing the authenticated-user attack surface.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html">Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)</a></p>
]]></content:encoded></item><item><title>Redis RCE Flaw CVE-2026-23479: Patch Now</title><link>https://zxcloudsecurity.co.uk/posts/redis-rce-use-after-free-cve-2026-23479/</link><pubDate>Wed, 03 Jun 2026 16:40:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/redis-rce-use-after-free-cve-2026-23479/</guid><description>CVE-2026-23479 is a 2-year-old use-after-free RCE vulnerability in Redis 7.2.0+. Learn the risk and how to protect your cloud infrastructure.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html">The Hacker News</a></p>
<hr>
<p>A use-after-free vulnerability in Redis (CVE-2026-23479) allows an authenticated user to execute arbitrary operating system commands on the host machine. Present in every stable Redis branch since version 7.2.0, the flaw went undetected for over two years before being discovered by an autonomous AI-powered code analysis tool. Because Redis is widely deployed as a caching and session layer in cloud environments, successful exploitation could lead to full host compromise.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Patch Redis to the May 5 release immediately across all environments — prioritise internet-adjacent or multi-tenant deployments. In the interim, enforce strict network segmentation so that only authorised application services can reach Redis, and audit whether any Redis instances permit external or untrusted client authentication.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html">Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)</a></p>
]]></content:encoded></item><item><title>CVE-2025-29923: go-redis Out-of-Order Response Flaw</title><link>https://zxcloudsecurity.co.uk/posts/cve-2025-29923-go-redis-out-of-order-response-client-setinfo/</link><pubDate>Wed, 03 Jun 2026 08:41:38 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2025-29923-go-redis-out-of-order-response-client-setinfo/</guid><description>CVE-2025-29923 in go-redis can cause out-of-order responses when CLIENT SETINFO times out. Learn the risk and remediation steps.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29923">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2025-29923 affects go-redis, a popular Go client library for Redis, where a timeout during the CLIENT SETINFO command at connection establishment can cause responses to be returned out of order. This race condition can result in a client receiving incorrect data, potentially leading to data corruption or unintended application behaviour. Applications using go-redis in Azure or other cloud environments that rely on connection pooling may be silently affected.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Audit any workloads using the go-redis library and upgrade to the patched version as soon as possible. Pay particular attention to services with high connection churn or aggressive connection timeouts, as these are most likely to trigger the out-of-order response condition.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29923">CVE-2025-29923 go-redis allows potential out of order responses when <code>CLIENT SETINFO</code> times out during connection establishment</a></p>
]]></content:encoded></item></channel></rss>