Redis 8.x — End of Life

EOL soon High risk
6 releases in this series3 CVEs

Redis 8.x is still supported and has no announced end-of-life date yet. The most recent release in this series is 8.10.2. 3 CVEs are tracked for this series.

Redis 8.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
8.10Jul 29, 2026—No8.10.2Active
8.8May 25, 2026Jul 29, 2026No8.8.3Active
8.6Feb 11, 2026May 25, 2026No8.6.7Active
8.4Nov 18, 2025Feb 11, 2026No8.4.7Active
8.2Aug 4, 2025Nov 18, 2025Sep 1, 20308.2.10Active
8.0May 2, 2025Aug 4, 2025Dec 1, 20268.0.6EOL soon

CVEs affecting Redis 8.x (12)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-25243HIGH8.83.66%—8.6Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not proper…May 5, 2026
CVE-2026-25243HIGH8.83.66%—8.4Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not proper…May 5, 2026
CVE-2026-25243HIGH8.83.66%—8.2Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not proper…May 5, 2026
CVE-2026-25243HIGH8.83.66%—8.0Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not proper…May 5, 2026
CVE-2026-23631HIGH8.12.80%—8.0Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke…May 5, 2026
CVE-2026-23631HIGH8.12.80%—8.6Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke…May 5, 2026
CVE-2026-23631HIGH8.12.80%—8.2Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke…May 5, 2026
CVE-2026-23631HIGH8.12.80%—8.4Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke…May 5, 2026
CVE-2026-23479HIGH8.81.50%—8.0Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not han…May 5, 2026
CVE-2026-23479HIGH8.81.50%—8.4Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not han…May 5, 2026
CVE-2026-23479HIGH8.81.50%—8.2Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not han…May 5, 2026
CVE-2026-23479HIGH8.81.50%—8.6Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not han…May 5, 2026

Add a Redis 8 EOL badge to your README

Show your users which Redis version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Redis 8 EOL status
[![Redis 8 EOL status](https://eolcanary.com/badge/redis/8.svg)](https://eolcanary.com/explore/redis/8)

Frequently asked questions

Is Redis 8 end of life?

No. Redis 8.x is still supported. It continues to receive security patches and bug fixes.

What CVEs affect Redis 8?

There are 3 CVEs tracked for Redis 8.x. See the full list above with CVSS and EPSS scores.

What is the latest Redis 8 version?

The latest Redis 8.x patch release is 8.10.2, released on September 17, 2026. Always run the latest patch to benefit from all security fixes.

When was Redis 8 first released?

Redis 8.0 was released on May 2, 2025. See the full version timeline in the table above.

Is it safe to run Redis 8 in production?

Yes, Redis 8 is still supported. Make sure you run the latest patch (8.10.2) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA