Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-32023 — Exploit for CVE-2025-32023 | Kitploit
Tools/GitHubGitHub/lordbheem/cve-2025-32023
Vulnerability AnalysisExploitationPenetration TestingLearning & EducationRed TeamingRemote Access Tool
GitHublordbheem/cve-2025-32023

CVE-2025-32023

Exploit for CVE-2025-32023

View Repository
361 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-32023

Remote Code Execution in Redis HyperLogLog Operations

Vulnerability Summary

CVE-2025-32023 is a remote code execution (RCE) vulnerability in the Redis database, specifically affecting the handling of HyperLogLog data structure operations. This flaw allows an authenticated user to trigger a stack or heap-based out-of-bounds write by submitting crafted strings, potentially leading to arbitrary code execution on the server. The vulnerability stems from an integer overflow in the processing of sparse HyperLogLog encodings. It was reported by GitHub, Inc. (specific discoverer not publicly disclosed) and has been present in Redis since version 2.8.

  • CVE-ID: CVE-2025-32023
  • Component: Redis
  • Type: Remote Code Execution (RCE)
  • CVSS Score: 7.0 (High)
  • Discovered by: GitHub, Inc.

Impact

An authenticated attacker with access to a vulnerable Redis instance can exploit this vulnerability to execute arbitrary code on the server, potentially leading to full system compromise. This could result in unauthorized access to sensitive data, installation of persistent backdoors, or disruption of services. The vulnerability is particularly critical in environments where Redis is used for high-performance caching or data processing, as it may expose critical infrastructure to attacks.

Proof of Concept

Exploit

This repository contains an exploit script for CVE-2025-32023. Replace the placeholder commands below with the specific instructions for running your script.

# Example usage (replace with actual commands for your script):
git clone https://github.com/atomicjjbod/CVE-2025-32023.git
cd CVE-2025-32023
chmod +x exploit
./exploit --host <redis_host> --port <redis_port>

Note: Ensure you have the necessary dependencies installed (e.g., Python, Redis client libraries). Test the exploit in a controlled environment to avoid unintended consequences.

Affected Versions

  • Vulnerable: Redis 2.8 to versions prior to 8.0.3, 7.4.5, 7.2.10, and 6.2.19
  • Patched: Redis 8.0.3, 7.4.5, 7.2.10, 6.2.19, and later
  • Not affected: Versions prior to 2.8

Mitigation

  • Update Redis: Upgrade to a patched version (8.0.3, 7.4.5, 7.2.10, or 6.2.19, depending on your branch) to address the vulnerability.
  • Restrict HyperLogLog Commands: Use Redis Access Control Lists (ACLs) to block execution of HyperLogLog-related commands (e.g., PFADD, PFCOUNT, PFMERGE). Example ACL configuration:
    ACL SETUSER username -~pf*
    
  • Network Security: Restrict network access to Redis instances, allowing only trusted clients to connect.
  • Monitor Logs: Enable logging and monitor Redis logs for suspicious HyperLogLog command usage.
  • Least Privilege: Ensure Redis users are configured with minimal permissions to reduce the attack surface.
  • Audit Configurations: Regularly review Redis configurations to ensure secure settings, especially in environments with public-facing or multi-user instances.

Technical Details

The vulnerability arises from an integer overflow in the processing of sparse HyperLogLog encodings. Specifically, when iterating over sparse HyperLogLog data, the length counter (int i) can overflow to a negative value due to malformed input, leading to an out-of-bounds write on the stack or heap. This can be exploited to corrupt memory and execute arbitrary code, depending on the context (e.g., hllMerge uses stack-allocated structures, while hllSparseToDense uses heap-allocated structures).

The issue was fixed in Redis by adding bounds checks and correcting the handling of length counters in HyperLogLog operations. The fix is included in the following commit: Redis Commit 50188747.

References

  • NVD Entry
  • GitHub Security Advisory
  • Redis Commit Fix
  • RedPacket Security Alert
  • DEV Community Article

Usage Notes

  • Responsible Disclosure: This exploit script is provided for educational and testing purposes only. Do not use it in production environments or against systems without explicit permission.
  • Environment Setup: Ensure you test the exploit in a sandboxed environment to prevent unintended damage.
  • Customization: Update the Proof of Concept section with the exact commands and dependencies required to run your script.
  • Reporting: If you identify new attack vectors or improvements to this exploit, consider contributing to the repository or reporting findings responsibly.

Current Status

As of July 10, 2025, no widespread exploitation of CVE-2025-32023 has been reported in the wild. However, public proof-of-concept code is available, increasing the risk of targeted attacks. Redis users are urged to apply patches promptly and implement the recommended mitigations to secure their systems.

Download Tool