Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security fixes
- (CVE-2025-21605) Limit output buffer for unauthenticated clients (#1992)
Bug fixes
- Fix defrag crash when using FLUSHDB ASYNC in cluster mode (#1873)
- Fix memory leak in forgotten node ping ext code path (#1576)
- Fix module LatencyAddSample still work when latency-monitor-threshold is 0 (#1541)
- Fix potential crash in radix tree recompression of huge keys (#1722)
- Fix error "SSL routines::bad length" when connTLSWrite is called second time with smaller buffer (#1737)
- Fix RANDOMKEY infinite loop during CLIENT PAUSE (#1850)
- fix: add samples to stream object consumer trees (#1825)
- Fix panic in primary when blocking shutdown after previous block with timeout (#1948)
- Fix incorrect lag reported in XINFO GROUPS (#1952)
Full Changelog: 7.2.8...7.2.9