Vulnerability Report: GO-2025-3540
- CVE-2025-29923, GHSA-92cp-5422-2mw7
- Affects: github.com/redis/go-redis, github.com/redis/go-redis, and 6 more
- Published: Mar 26, 2025
Potential out of order responses when CLIENT SETINFO times out during connection establishment in github.com/redis/go-redis
For detailed information about this vulnerability, visit https://github.com/redis/go-redis/security/advisories/GHSA-92cp-5422-2mw7.
Affected Packages
-
PathGo VersionsCustom Versions*Symbols
-
all versions, no known fixed-
5 unexported affected symbols
- baseClient.initConn
- redis.ClusterOptions
- redis.FailoverOptions
- redis.RingOptions
- redis.UniversalOptions
-
from v9.5.1 before v9.5.5-
5 unexported affected symbols
- baseClient.initConn
- redis.ClusterOptions
- redis.FailoverOptions
- redis.RingOptions
- redis.UniversalOptions
-
before v9.6.3-
5 unexported affected symbols
- baseClient.initConn
- redis.ClusterOptions
- redis.FailoverOptions
- redis.RingOptions
- redis.UniversalOptions
-
from v9.7.0-beta.1 before v9.7.3-
5 unexported affected symbols
- baseClient.initConn
- redis.ClusterOptions
- redis.FailoverOptions
- redis.RingOptions
- redis.UniversalOptions
Affected Modules
-
PathGo VersionsCustom Versions*
-
all versions, no known fixed-
-
all versions, no known fixed-
-
all versions, no known fixed-
-
all versions, no known fixed-
*Custom versions, which can't be mapped automatically to standard Go module versions, are ignored by govulncheck
. (See this note on versions for more details.)
Aliases
References
- https://github.com/redis/go-redis/security/advisories/GHSA-92cp-5422-2mw7
- https://github.com/redis/go-redis/commit/d236865b0cfa1b752ea4b7da666b1fdcd0acebb6
- https://github.com/redis/go-redis/pull/3295
- https://vuln.go.dev/ID/GO-2025-3540.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.