Catalog / Databases

Redis changelog

Redis is at 8.10.1, published 17 Aug 2026, 28 days ago.

In memory data store used as a cache, a message broker and a database, with values that are lists, sets, hashes and streams rather than rows.

SubscribeRedis as markdown, for pasting into a model
Collected
60 releases back to 23 Apr 2025
Source
redis/redis
Project
redis.io
Advisories
47 published newest 2026
Feed
RSS

Every release of a major line in one list, which is the one view the publisher never writes: 7 to 8. Only the lines whose first release the archive holds are listed, because a partial major would read as the whole of one.

Read today, the first day on record. Collection status

Version history

8.x36 releases
8.10.1

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-a

securityfixedchanged
8.8.2

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-a

securityfixedchanged
8.6.6

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-a

securityfixedchanged
8.4.6

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-a

securityfixedchanged
8.2.9

Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-after-free in the TLS pending-data list when a command closes anothe

securityfixed
8.10.0

This is the General Availability release of Redis 8.10 in Redis Open Source. Major changes compared to 8.8 Compact hashes - a new hash encoding that reduces memory usage by storing hash field names just once for keys that share a schema New

addedfixed
8.8.1

SECURITY: There is a security fix in the release. Security fixes RedisBloom/RedisBloom#1044 Crafted RESTORE payloads in RedisBloom and TDigest may trigger out-of-bounds writes, potentially leading to remote code execution

securityfixed
8.6.5

SECURITY: There are security fixes in the release. Security fixes A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution RedisBloom/RedisBloom#1046 C

securityfixed
8.4.5

SECURITY: There are security fixes in the release. Security fixes A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution RedisBloom/RedisBloom#1039 C

securityfixed
8.2.8

SECURITY: There are security fixes in the release. Security fixes A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution RedisBloom/RedisBloom#1041 C

securityfixed
8.6.4

Update urgency: HIGH: There are critical bugs that may affect a subset of users. Bug fixes #15175, RediSearch/RediSearch#9262 Redis fails to start on AArch64 #15163 MULTI queue memory incorrect memory accounting #15115 Under-copy in the Lua

fixedchanged
8.4.4

Update urgency: HIGH: There are critical bugs that may affect a subset of users. Bug fixes #15175, RediSearch/RediSearch#9262 Redis fails to start on AArch64 #15163 MULTI queue memory incorrect memory accounting #14581 Rare server hang at s

fixedchanged
8.2.7

Update urgency: HIGH: There are critical bugs that may affect a subset of users. Bug fixes #15175, RediSearch/RediSearch#9262 Redis fails to start on AArch64 #14537 SCAN: restore original filter order (revert change introduced in 8.2) #1481

fixedchanged
8.8.0

This is the General Availability release of Redis 8.8 in Redis Open Source. Major changes compared to 8.6 New data structure: Array (@antirez) Subkey notification for hash fields - field-level notifications INCREX: a window counter rate lim

addedfixedchanged
8.6.3

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-23479) Use-After-Free in unblock client flow may lead to Remote Code Execution (CVE-2026-25243) Invalid memory access in RESTORE may lead to Remote

securityfixedchanged
8.4.3

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-23479) Use-After-Free in unblock client flow may lead to Remote Code Execution. (CVE-2026-25243) Invalid memory access in RESTORE may lead to Remote

securityfixedchanged
8.2.6

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-23479) Use-After-Free in unblock client flow may lead to Remote Code Execution. (CVE-2026-25243) Invalid memory access in RESTORE may lead to Remote

securityfixedchanged
8.6.2

Bug fixes #14824 Potential UAF: don't use reply copy avoidance for module strings #14848 Crash during command processing on replicas performing full synchronization #14794 New XIDMPRECORD internal command and AOFRW emission to restore strea

addedfixed
8.6.1

SECURITY: There is a security fix in the release Security fixes A user can manipulate data read by a connection by injecting \r\n sequences into a Redis error reply Bug fixes #14785 HOTKEYS: The INFO command may display module information,

securityfixed
8.4.2

SECURITY: There is a security fix in the release Security fixes A user can manipulate data read by a connection by injecting \r\n sequences into a Redis error reply

securityfixed
8.2.5

SECURITY: There is a security fix in the release Security fixes A user can manipulate data read by a connection by injecting \r\n sequences into a Redis error reply

securityfixed
8.0.6

SECURITY: There is a security fix in the release Security fixes A user can manipulate data read by a connection by injecting \r\n sequences into a Redis error reply

securityfixed
8.6.0

This is the General Availability release of Redis 8.6 in Redis Open Source. Major changes compared to 8.4 Substantial performance improvements Substantial memory reduction for hashes (hashtable-encoded) and sorted sets (skiplist-encoded) St

addedfixedremoved
8.4.1

Update urgency: SECURITY: There are security fixes in the release. Security fixes RedisTimeSeries/RedisTimeSeries#1837, RedisJSON/RedisJSON#1474 Hide Personally Identifiable Information from server log RedisBloom/RedisBloom#936 Cuckoo filte

securityaddedfixed
8.2.4

Update urgency: SECURITY: There are security fixes in the release. Security fixes RedisTimeSeries/RedisTimeSeries#1837, RedisJSON/RedisJSON#1474 Hide Personally Identifiable Information from server log Bug fixes RedisJSON/RedisJSON#1430 Mal

securityaddedfixed
8.4.0

This is the General Availability release of Redis 8.4 in Redis Open Source. Major changes compared to 8.2 DIGEST, DELEX; SET extensions - atomic compare-and-set and compare-and-delete for string keys MSETEX - atomically set multiple string

addedfixedchanged
8.2.3

Update urgency: SECURITY: There is a security fix in the release. Security fixes (CVE-2025-62507) XACKDEL - potential stack overflow and RCE Bug fixes HGETEX - potential crash when FIELDS is used and numfields is missing Potential crash on

securityfixedchanged
8.0.5

Update urgency: HIGH: There are critical bugs that may affect a subset of users. Bug fixes HGETEX - potential crash when FIELDS is used and numfields is missing Potential crash on HyperLogLog with 2GB+ entries Cuckoo filter - Division by ze

securityfixedchanged
8.2.2

Update urgency: SECURITY: There are security fixes in the release Security fixes (CVE-2025-49844) A Lua script may lead to remote code execution (CVE-2025-46817) A Lua script may lead to integer overflow and potential RCE (CVE-2025-46818) A

securityaddedfixed
8.0.4

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-49844) A Lua script may lead to remote code execution (CVE-2025-46817) A Lua script may lead to integer overflow and potential RCE (CVE-2025-46818)

securityaddedfixed
8.2.1

Update urgency: MODERATE: Program an upgrade of the server, but it's not urgent. Bug fixes #14240 INFO KEYSIZES - potential incorrect histogram updates on cluster mode with modules #14274 Disable Active Defrag during flushing replica #14276

fixedchangedremoved
8.2.0

This is the General Availability release of Redis 8.2 in Redis Open Source. Major changes compared to 8.0 Streams - new commands: XDELEX and XACKDEL; extension to XADD and XTRIM Bitmap - BITOP: new operators: DIFF, DIFF1, ANDOR, and ONE Que

securityaddedfixed
8.0.3

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-32023) Fix out-of-bounds write in HyperLogLog commands (CVE-2025-48367) Retry accepting other connections even if the accepted connection reports an

securityaddedfixed
8.0.2

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-27151) redis-check-aof may lead to stack overflow and potential RCE Bug fixes #14081 Cron-based timers run twice as fast when active defrag is enabl

securityfixedchanged
8.0.1

Update urgency: MODERATE: Program an upgrade of the server, but it's not urgent. Performance and resource utilization improvements #13959 Vector sets - faster VSIM FILTER parsing Bug fixes #Q6083 Query Engine - revert default policy search-

fixedchanged
8.0.0

This is the General Availability release of Redis 8.0 in Redis Open Source. Redis 8.0 deprecates previous Redis and Redis Stack versions. Stand alone RediSearch, RedisJSON, RedisTimeSeries, and RedisBloom are no longer needed as they are no

securityaddedfixed
7.x18 releases
7.4.11

Update urgency: SECURITY: There are security fixes in the release. Security fixes Use-after-free in the TLS pending-data list when a command closes another pending connection #15478 ACL key permission bypass in SORT, GEORADIUS/GEORADIUSBYME

securityfixedchanged
7.2.16

Update urgency: SECURITY: There are security fixes in the release. Security fixes Use-after-free in the TLS pending-data list when a command closes another pending connection ACL key permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER an

securityfixedchanged
7.4.10

Update urgency: SECURITY: There is a security fix in the release. Security fixes A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution

securityfixedchanged
7.2.15

Update urgency: SECURITY: There is a security fix in the release. Security fixes A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution

securityfixedchanged
7.4.9

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-23479) Use-After-Free in unblock client flow may lead to Remote Code Execution. (CVE-2026-25243) Invalid memory access in RESTORE may lead to Remote

securityfixedchanged
7.2.14

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-23479) Use-After-Free in unblock client flow may lead to Remote Code Execution. (CVE-2026-25243) Invalid memory access in RESTORE may lead to Remote

securityfixedchanged
7.4.8

SECURITY: There is a security fix in the release Security fixes A user can manipulate data read by a connection by injecting \r\n sequences into a Redis error reply

securityfixed
7.2.13

SECURITY: There is a security fix in the release Security fixes A user can manipulate data read by a connection by injecting \r\n sequences into a Redis error reply

securityfixed
7.4.7

Update urgency: HIGH: There is a critical bug that may affect a subset of users. Bug fixes Potential crash on HyperLogLog with 2GB+ entries

fixedchanged
7.2.12

Update urgency: HIGH: There is a critical bug that may affect a subset of users. Bug fixes Potential crash on HyperLogLog with 2GB+ entries

fixedchanged
7.2.11

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-49844) A Lua script may lead to remote code execution (CVE-2025-46817) A Lua script may lead to integer overflow and potential RCE (CVE-2025-46818)

securityfixedchanged
7.4.6

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-49844) A Lua script may lead to remote code execution (CVE-2025-46817) A Lua script may lead to integer overflow and potential RCE (CVE-2025-46818)

securityfixedchanged
7.4.5

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-32023) Fix out-of-bounds write in HyperLogLog commands (CVE-2025-48367) Retry accepting other connections even if the accepted connection reports an

securityfixedchanged
7.2.10

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-32023) Fix out-of-bounds write in HyperLogLog commands (CVE-2025-48367) Retry accepting other connections even if the accepted connection reports an

securityfixedchanged
7.4.4

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-27151) redis-check-aof may lead to stack overflow and potential RCE Bug fixes #13966, #13932 CLUSTER SLOTS - TLS port update not reflected in CLUSTE

securityfixedchanged
7.2.9

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-27151) redis-check-aof may lead to stack overflow and potential RCE Bug fixes #13966, #13932 CLUSTER SLOTS - TLS port update not reflected in CLUSTE

securityfixedchanged
7.4.3

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-21605) An unauthenticated client can cause an unlimited growth of output buffers Bug fixes #13661 FUNCTION FLUSH - memory leak when using jemalloc #

securityfixedchanged
7.2.8

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-21605) An unauthenticated client can cause an unlimited growth of output buffers Bug fixes #12817, #12905 Fix race condition issues between the main

securityfixedchanged
6.x6 releases
6.2.24

Update urgency: SECURITY: There is a security fix in the release. Security fixes Use-after-free in the TLS pending-data list when a command closes another pending connection

securityfixedchanged
6.2.23

Update urgency: SECURITY: There is a security fix in the release. Security fixes A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution

securityfixedchanged
6.2.22

Update urgency: SECURITY: There is a security fix in the release. Security fixes (CVE-2026-25243) Invalid memory access in RESTORE may lead to Remote Code Execution Bug fixes SUBSCRIBE, PSUBSCRIBE, SSUBSCRIBE: crash on OOM (RED-167788) SCRI

securityfixedchanged
6.2.21

Update urgency: HIGH: There is a critical bug that may affect a subset of users. Bug fixes Potential crash on HyperLogLog with 2GB+ entries

fixedchanged
6.2.20

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-49844) A Lua script may lead to remote code execution (CVE-2025-46817) A Lua script may lead to integer overflow and potential RCE (CVE-2025-46818)

securityfixedchanged
6.2.19

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-32023) Fix out-of-bounds write in HyperLogLog commands (CVE-2025-48367) Retry accepting other connections even if the accepted connection reports an

securityfixedchanged