CVE-2025-67733
Valkey Affected by RESP Protocol Injection via Lua error_reply
7.1
HIGH
CVSS 3.1
EPSS 0.02%
Description
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.
How to fix CVE-2025-67733
To remediate CVE-2025-67733, upgrade the affected package to a fixed version below.
- —upgrade to 7.2.12-r0 or later
- —upgrade to 7.2.12 or later
- —upgrade to 7.3.6+ds-2 or later
- —upgrade to 5:7.0.15-1~deb12u7 or later
- —upgrade to 8.1.1+dfsg1-3+deb13u2 or later
Is CVE-2025-67733 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (5)
- from 0, < 7.2.12-r0
- from 0, < 7.2.12, >= 8.0.0, < 8.0.7, >= 8.1.0, < 8.1.6, >= 9.0.0, < 9.0.2
- from 0, < 7.3.6+ds-2
- from 0, < 5:7.0.15-1~deb12u7
- from 0, < 8.1.1+dfsg1-3+deb13u2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H |