Redis has responded to public claims by researchers who used the Kimi K3 AI model to identify 19 zero-day vulnerabilities in Redis. Of the publicly documented issues, three were confirmed: a Redis Streams use-after-free, a RedisBloom TDigest out-of-bounds write, and a RedisBloom TopK RDB loader wild-free. All three had already been reported via Redis's bug bounty program by unaffiliated researchers. Redis expedited fixes, releasing Redis 8.8.1 and updates for six older branches, plus RedisBloom security releases. The TopK issue has been patched in Redis Software and Redis Cloud, with an open source fix coming soon. Users are urged to update immediately and follow recommended security practices including strong authentication and network isolation.
762 Impressions1 Comment