- Fixed a security vulnerability where crafted CRLF sequences in Redis error replies could be used to manipulate data read by a connection.
- Improved handling of Redis error messages to sanitize injected newline characters.
No matching updates in this bucket.
Python updates in 2026-w09
- Fix a vulnerability where CR\r\n sequences could be injected into Redis error replies, allowing data manipulation by a malicious user.
- Apply a security patch to sanitize error responses, preventing manipulation of connection data.
- Fix prevents data manipulation by injecting CRLF sequences into Redis error replies
- Ensures connections cannot be tricked into reading tampered data
- Fix for CRLF injection in Redis error replies
- Prevents malicious manipulation of data read by connections
- Fixed a security issue where injected CRLF sequences could manipulate data read from Redis error replies.
- Added the missing HOTKEYS HELP subcommand and ensured INFO correctly displays module information.
- Resolved an RDB loading bug that prevented hash table expansion, reducing load times.