Redis 7.x — End of Life
Active High riskRedis 7.x is partially supported: only 7.4, 7.2 still receive security fixes, the longest-lived (7.4) until Dec 1, 2029, in 1151 days. The most recent release in this series is 7.4.11. 3 CVEs are tracked for this series. 2 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Redis 8. See Redis 8 →
Redis 7.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 7.4 | Jul 29, 2024 | May 2, 2025 | Dec 1, 2029 | 7.4.11 | Active | |
| 7.2 | Aug 15, 2023 | Jul 29, 2024 | Dec 1, 2029 | 7.2.16 | Active | |
| 7.0 | Apr 27, 2022 | Aug 15, 2023 | Jul 29, 2024 | 7.0.15 | EOL |
CVEs affecting Redis 7.x (8)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-25243 | HIGH | 8.8 | 3.66% | — | 7.0 | Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not proper… | May 5, 2026 |
| CVE-2026-25243 | HIGH | 8.8 | 3.66% | — | 7.2 | Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not proper… | May 5, 2026 |
| CVE-2026-25243 | HIGH | 8.8 | 3.66% | — | 7.4 | Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not proper… | May 5, 2026 |
| CVE-2026-23631 | HIGH | 8.1 | 2.80% | — | 7.4 | Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke… | May 5, 2026 |
| CVE-2026-23631 | HIGH | 8.1 | 2.80% | — | 7.2 | Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke… | May 5, 2026 |
| CVE-2026-23631 | HIGH | 8.1 | 2.80% | — | 7.0 | Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke… | May 5, 2026 |
| CVE-2026-23479 | HIGH | 8.8 | 1.50% | — | 7.4 | Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not han… | May 5, 2026 |
| CVE-2026-23479 | HIGH | 8.8 | 1.50% | — | 7.2 | Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not han… | May 5, 2026 |
Redis 7.x will reach end of life — migrate to Redis 8.x
Redis 8.x is the next major release. Plan your upgrade before Redis 7.x stops receiving security patches.
Add a Redis 7 EOL badge to your README
Show your users which Redis version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/redis/7)Frequently asked questions
Is Redis 7 end of life?
Partially. 1 of the 3 Redis 7.x releases have reached end of life. Still supported: 7.4, 7.2 (until December 1, 2029 at the latest).
What CVEs affect Redis 7?
There are 3 CVEs tracked for Redis 7.x. See the full list above with CVSS and EPSS scores.
What is the latest Redis 7 version?
The latest Redis 7.x patch release is 7.4.11, released on August 17, 2026. Always run the latest patch to benefit from all security fixes.
How to migrate from Redis 7 to Redis 8?
To migrate from Redis 7 to Redis 8: (1) review the official Redis 8 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Redis 7 in production?
Only on a supported release (7.4, 7.2). Support for Redis 7.4 ends on December 1, 2029. Make sure you run the latest patch (7.4.11) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
