CVE-2025-67733 is an improper CR/LF handling vulnerability in Valkey Lua-script error processing. Before Valkey 9.0.2, 8.1.6, 8.0.7, and 7.2.12, error replies generated through Lua scripting commands can include attacker-controlled CR/LF sequences. Because RESP frames use CRLF delimiters, injected sequences can be parsed as unrelated responses on the same client connection, allowing response-stream injection and tampering with data returned by subsequent commands.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small proof-of-concept demonstrating RESP protocol injection (socket buffer poisoning) in a scenario where a web backend reuses a single Valkey/Redis TCP connection and performs incorrect/partial parsing of server replies. Structure/purpose: - backend.py: Flask app exposing three endpoints: POST/GET /api/user/role and POST /api/process. It maintains a global shared TCP socket to Valkey/Redis and manually crafts RESP commands (AUTH/SET/GET/EVAL). The vulnerable behavior is in process_script(): after sending EVAL it reads only the first line of the error reply (up to CRLF), leaving remaining bytes in the socket receive buffer. - attacker_client.py: Sends a POST to /api/process with a Lua script that raises an error whose message contains embedded CRLF and RESP bulk-string framing ("INJECTED\r\n$11\r\nhacked_user"). This causes the backend to read "-ERR INJECTED" as the error line while leaving "$11\r\nhacked_user" queued in the socket buffer. - victim_client.py: Normal client that POSTs to /api/user/role to set a role and GETs /api/user/role to retrieve it. After the attacker poisons the buffer, the victim’s subsequent GET reads the leftover "$11\r\nhacked_user" as if it were the response to GET, resulting in the victim receiving role "hacked_user". Main exploit capability: - Cross-request response smuggling on a shared Valkey/Redis connection: attacker-controlled bytes from an EVAL error reply are interpreted as the next command’s response, enabling data integrity compromise (wrong values returned) and potentially broader request/response desynchronization depending on what the backend does with subsequent replies.
Repository is a small Python proof-of-concept demonstrating RESP protocol injection / response desynchronization against a Valkey/Redis backend when an application reuses a shared TCP connection and performs incorrect/incomplete RESP parsing. Structure and purpose: - README.md: Explains the attack concept and step-by-step demo. - backend.py: Flask web app that maintains a single global TCP socket to Valkey/Redis (simulating connection pooling). Implements: - POST /api/user/role: sends raw RESP SET for key user:{username}:role. - GET /api/user/role: sends raw RESP GET and parses the response. - POST /api/process: sends raw RESP EVAL with user-supplied Lua script. The vulnerability is intentionally modeled in /api/process: it reads only the first line of the error reply (up to \r\n) and returns, leaving remaining bytes in the socket receive buffer. - attacker_client.py: Sends a malicious Lua script to /api/process that raises an error containing CRLF and a crafted RESP bulk-string header/value. This causes the backend to consume only "-ERR INJECTED\r\n" while leaving "$11\r\nhacked_user" queued. - victim_client.py: Normal client that sets role to "normal_user" and later retrieves it. After the attacker poisons the socket, the victim’s subsequent GET reads the leftover "$11\r\nhacked_user" as if it were the GET response, resulting in the backend returning role "hacked_user". Exploit capabilities: - Network-based attack via HTTP to the backend. - Protocol-level injection into RESP stream using Lua error messages (EVAL) to smuggle additional RESP frames. - Demonstrates cross-request impact on other users due to shared connection state (socket poisoning), effectively allowing an attacker to influence subsequent responses returned to victims (data integrity violation / response confusion).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.