Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 25 Feb 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lfprojects
Lfprojects valkey |
|
| CPEs | cpe:2.3:a:lfprojects:valkey:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lfprojects
Lfprojects valkey |
Wed, 25 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-170 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 24 Feb 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Valkey-io
Valkey-io valkey |
|
| Vendors & Products |
Valkey-io
Valkey-io valkey |
Mon, 23 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. | |
| Title | Valkey Affected by RESP Protocol Injection via Lua error_reply | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-25T14:57:21.038Z
Reserved: 2025-12-11T00:45:45.790Z
Link: CVE-2025-67733
Updated: 2026-02-25T14:57:11.057Z
Status : Analyzed
Published: 2026-02-23T20:28:53.280
Modified: 2026-02-25T17:34:02.743
Link: CVE-2025-67733
OpenCVE Enrichment
Updated: 2026-02-24T09:55:28Z