0-day
Public PoCs target stock Redis releases, including the newly patched 8.8.1. The authors say China’s Kimi K3 found 19 zero-days and built one exploit in 27 minutes.
Redis shipped seven security releases on July 23 after working remote-code-execution exploits appeared for stock versions. By the following day, the researchers behind those exploits were claiming they could also break Redis 8.8.1, the newest of the seven patched releases.
Researchers including Fuzzland Co-Founder Chaofan Shou claimed agents powered by Kimi K3, the flagship model from China’s Moonshot AI, found 19 Redis zero-days in 90 minutes and turned one into a working exploit in 27 minutes.
Redis did not immediately respond to that claim, or questions from The Stack about whether its patches were directly prompted by the research, whether it had received the vulnerabilities privately before the PoCs appeared, or whether Redis 8.8.1 remains vulnerable.
Redis is often used as a cache in front of conventional databases to speed up websites and services, with its low-latency approach of keeping frequently needed data in RAM. But it is also used for session storage, message queues, real-time counters, leaderboards, streaming and, increasingly, vector search for AI applications. Though challenged by Linux Foundation’s Valkey, it is still dominant in its niche.
Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.
Already a member? Sign in