Catalog / Redis

Redis 7 to 8

Every Redis 8.x release the archive holds, 36 of them, starting at 8.0.0 and running to 8.10.1. The publisher writes these one at a time and its documentation describes the version you are on, so the run between two majors is not laid out anywhere as a list.

Releases
36 36 carry notes
Opened
2 May 2025 1.4 years ago
Span
16 months to 17 Aug 2026
Breaking
0 none tagged
Advisories closed
1 security

The turn

The last 7.x release the archive holds before the turn is 7.4.3, on 23 Apr 2025. 8.0.0 followed 9 days later. 7.x did not stop there. 16 more 7.x releases shipped after 8.0.0 opened, the last of them on 17 Aug 2026, so both lines were being maintained at once.

Every 8.x release

All Redis releases
8.10.1securityfixedchanged

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-a

8.8.2securityfixedchanged

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-a

8.6.6securityfixedchanged

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-a

8.4.6securityfixedchanged

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-a

8.2.9securityfixed

Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-after-free in the TLS pending-data list when a command closes anothe

8.10.0addedfixed

This is the General Availability release of Redis 8.10 in Redis Open Source. Major changes compared to 8.8 Compact hashes - a new hash encoding that reduces memory usage by storing hash field names just once for keys that share a schema New

8.8.1securityfixed

SECURITY: There is a security fix in the release. Security fixes RedisBloom/RedisBloom#1044 Crafted RESTORE payloads in RedisBloom and TDigest may trigger out-of-bounds writes, potentially leading to remote code execution

8.6.5securityfixed

SECURITY: There are security fixes in the release. Security fixes A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution RedisBloom/RedisBloom#1046 C

8.4.5securityfixed

SECURITY: There are security fixes in the release. Security fixes A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution RedisBloom/RedisBloom#1039 C

8.2.8securityfixed

SECURITY: There are security fixes in the release. Security fixes A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution RedisBloom/RedisBloom#1041 C

8.6.4fixedchanged

Update urgency: HIGH: There are critical bugs that may affect a subset of users. Bug fixes #15175, RediSearch/RediSearch#9262 Redis fails to start on AArch64 #15163 MULTI queue memory incorrect memory accounting #15115 Under-copy in the Lua

8.4.4fixedchanged

Update urgency: HIGH: There are critical bugs that may affect a subset of users. Bug fixes #15175, RediSearch/RediSearch#9262 Redis fails to start on AArch64 #15163 MULTI queue memory incorrect memory accounting #14581 Rare server hang at s

8.2.7fixedchanged

Update urgency: HIGH: There are critical bugs that may affect a subset of users. Bug fixes #15175, RediSearch/RediSearch#9262 Redis fails to start on AArch64 #14537 SCAN: restore original filter order (revert change introduced in 8.2) #1481

8.8.0addedfixedchanged

This is the General Availability release of Redis 8.8 in Redis Open Source. Major changes compared to 8.6 New data structure: Array (@antirez) Subkey notification for hash fields - field-level notifications INCREX: a window counter rate lim

8.6.3securityfixedchanged

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-23479) Use-After-Free in unblock client flow may lead to Remote Code Execution (CVE-2026-25243) Invalid memory access in RESTORE may lead to Remote

8.4.3securityfixedchanged

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-23479) Use-After-Free in unblock client flow may lead to Remote Code Execution. (CVE-2026-25243) Invalid memory access in RESTORE may lead to Remote

8.2.6securityfixedchanged

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-23479) Use-After-Free in unblock client flow may lead to Remote Code Execution. (CVE-2026-25243) Invalid memory access in RESTORE may lead to Remote

8.6.2addedfixed

Bug fixes #14824 Potential UAF: don't use reply copy avoidance for module strings #14848 Crash during command processing on replicas performing full synchronization #14794 New XIDMPRECORD internal command and AOFRW emission to restore strea

8.6.1securityfixed

SECURITY: There is a security fix in the release Security fixes A user can manipulate data read by a connection by injecting \r\n sequences into a Redis error reply Bug fixes #14785 HOTKEYS: The INFO command may display module information,

8.4.2securityfixed

SECURITY: There is a security fix in the release Security fixes A user can manipulate data read by a connection by injecting \r\n sequences into a Redis error reply

8.2.5securityfixed

SECURITY: There is a security fix in the release Security fixes A user can manipulate data read by a connection by injecting \r\n sequences into a Redis error reply

8.0.6securityfixed

SECURITY: There is a security fix in the release Security fixes A user can manipulate data read by a connection by injecting \r\n sequences into a Redis error reply

8.6.0addedfixedremoved

This is the General Availability release of Redis 8.6 in Redis Open Source. Major changes compared to 8.4 Substantial performance improvements Substantial memory reduction for hashes (hashtable-encoded) and sorted sets (skiplist-encoded) St

8.4.1securityaddedfixed

Update urgency: SECURITY: There are security fixes in the release. Security fixes RedisTimeSeries/RedisTimeSeries#1837, RedisJSON/RedisJSON#1474 Hide Personally Identifiable Information from server log RedisBloom/RedisBloom#936 Cuckoo filte

8.2.4securityaddedfixed

Update urgency: SECURITY: There are security fixes in the release. Security fixes RedisTimeSeries/RedisTimeSeries#1837, RedisJSON/RedisJSON#1474 Hide Personally Identifiable Information from server log Bug fixes RedisJSON/RedisJSON#1430 Mal

8.4.0addedfixedchanged

This is the General Availability release of Redis 8.4 in Redis Open Source. Major changes compared to 8.2 DIGEST, DELEX; SET extensions - atomic compare-and-set and compare-and-delete for string keys MSETEX - atomically set multiple string

8.2.3securityfixedchanged

Update urgency: SECURITY: There is a security fix in the release. Security fixes (CVE-2025-62507) XACKDEL - potential stack overflow and RCE Bug fixes HGETEX - potential crash when FIELDS is used and numfields is missing Potential crash on

8.0.5securityfixedchanged

Update urgency: HIGH: There are critical bugs that may affect a subset of users. Bug fixes HGETEX - potential crash when FIELDS is used and numfields is missing Potential crash on HyperLogLog with 2GB+ entries Cuckoo filter - Division by ze

8.2.2securityaddedfixed

Update urgency: SECURITY: There are security fixes in the release Security fixes (CVE-2025-49844) A Lua script may lead to remote code execution (CVE-2025-46817) A Lua script may lead to integer overflow and potential RCE (CVE-2025-46818) A

8.0.4securityaddedfixed

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-49844) A Lua script may lead to remote code execution (CVE-2025-46817) A Lua script may lead to integer overflow and potential RCE (CVE-2025-46818)

8.2.1fixedchangedremoved

Update urgency: MODERATE: Program an upgrade of the server, but it's not urgent. Bug fixes #14240 INFO KEYSIZES - potential incorrect histogram updates on cluster mode with modules #14274 Disable Active Defrag during flushing replica #14276

8.2.0securityaddedfixed

This is the General Availability release of Redis 8.2 in Redis Open Source. Major changes compared to 8.0 Streams - new commands: XDELEX and XACKDEL; extension to XADD and XTRIM Bitmap - BITOP: new operators: DIFF, DIFF1, ANDOR, and ONE Que

8.0.3securityaddedfixed

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-32023) Fix out-of-bounds write in HyperLogLog commands (CVE-2025-48367) Retry accepting other connections even if the accepted connection reports an

8.0.2securityfixedchanged

Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2025-27151) redis-check-aof may lead to stack overflow and potential RCE Bug fixes #14081 Cron-based timers run twice as fast when active defrag is enabl

8.0.1fixedchanged

Update urgency: MODERATE: Program an upgrade of the server, but it's not urgent. Performance and resource utilization improvements #13959 Vector sets - faster VSIM FILTER parsing Bug fixes #Q6083 Query Engine - revert default policy search-

8.0.0securityaddedfixed

This is the General Availability release of Redis 8.0 in Redis Open Source. Redis 8.0 deprecates previous Redis and Redis Stack versions. Stand alone RediSearch, RedisJSON, RedisTimeSeries, and RedisBloom are no longer needed as they are no