CVE-2025-67733 Details
Description
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.
A RESP protocol injection vulnerability has been identified in Valkey, a distributed key-value database, in versions prior to 9.0.2, 8.1.6, 8.0.7, and 7.2.12. The vulnerability allows a malicious user to inject arbitrary information into the response stream for a given client using scripting commands. This could potentially corrupt or tamper with data sent to other users on the same connection. The issue arises because the error handling code for Lua scripts does not properly manage null characters.
Users can upgrade to Valkey versions 9.0.2, 8.1.6, 8.0.7, or 7.2.12 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:3443 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:3507 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:5445 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2025-67733 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2442025 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-67733.json | redhat-SADP | |
| https://github.com/valkey-io/valkey/security/advisories/GHSA-p876-p7q5-hv2m | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-170 | Improper Null Termination | redhat-SADP |
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lfprojects valkey | < 7.2.12 >= 8.0.0, < 8.0.7 >= 8.1.0, < 8.1.6 >= 9.0.0, < 9.0.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2026 | Initial Analysis | [email protected] |
| Feb 23, 2026 | New CVE Received | [email protected] |