A AegiFlow
HIGHCVSS 7.0

CVE-2022-31144

CVE-2022-31144 updated by NVD

Modified
2026-09-20
Sources
nvd

Summary

Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.

Affected packages

EcosystemPackageAffected versionsFixed versions
Redisredis[object Object]

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.