Redis Stack 7.4 release notes
Redis Stack 7.4 release notes.
Redis Stack 7.4.0-v1 (October 2024)
This is a maintenance release for Redis Stack Server 7.4.0.
Update urgency: SECURITY
: there are security fixes in the release.
Headlines
This version includes security fixes for the Redis server, addressing potential vulnerabilities such as an RCE when using Lua library components, and a denial-of-service (DoS) risk due to malformed ACL selectors or unbounded pattern matching. Additionally, this maintenance release includes the latest version of Redis Insight.
Details
Security and privacy
- Redis:
- (CVE-2024-31449) Lua library commands may lead to stack overflow and potential RCE.
- (CVE-2024-31227) Potential Denial-of-service due to malformed ACL selectors.
- (CVE-2024-31228) Potential Denial-of-service due to unbounded pattern matching.
Redis Community Edition version
Module versions
Recommended client libraries
- Java
- Python
- NodeJS
- Go
Compatible with Redis Insight. The docker image redis/redis-stack for this version is bundled with Redis Insight 2.58.
Note: version numbers follow the pattern:
x.y.z-b
x.y
Redis Major versionz
increases with even numbers as a module x.y version increases.b
denotes a patch to Redis or a module (anyz
of Redis or modules).b
will consist of av
+ numeric value.
Redis Community Edition 7.4.0-v0 (July 2024)
This is a GA release of Redis Stack version 7.4.
Headlines
Data Structures
Hash
: Redis now supports expiration of individual hash fields. Redis already supports key expiration. For each key, users can specify a time when it should expire, or specify the remaining time-to-live (TTL) after which it would expire. One very frequent request was to allow specifying expiration time or TTL also for individual hash fields, which is now supported using nine new Redis commands:
HEXPIRE
,HPEXPIRE
,HEXPIREAT
,HPEXPIREAT
- set the time when specific hash fields should expire, or the remaining time-to-live for specific fields.HTTL
,HPTTL
,HEXPIRETIME
,HPEXPIRETIME
- retrieve the time when specific hash fields should expire, or the remaining time-to-live for specific fieldsHPERSIST
- remove the expiration of specific hash fields.
Streams
: It is now possible to start reading from the last stream message using XREAD
with the new id value +
.
There are many additional improvements, including new command arguments, security, performance, and resource utilization enhancements, several new metrics and configuration parameters were introduced, and multiple bugs were fixed.
Time series
: The latest time series data structure adds a highly requested feature: insertion-filter for close samples. Many sensors report data periodically. Often, the difference between the measured value and the previously measured value is negligible and related to random noise or to measurement accuracy limitations. When both the time difference and the value difference between the current and the previous sample are small, it may be preferable to ignore (not to add) the new measurement.
JSON
: Introduces a fix to avoid duplicating AOF commands multiple times in JSON.MSET
.
Probabilistic
: Now, an error is returned if CMS.MERGE
results in an overflow or underflow.
Search and query
- New
BFLOAT16
andFLOAT16
vector data types reduce memory consumed by vectors while preserving accuracy. - Support for indexing empty and missing values and enhanced developer experience for queries with exact matching capabilities.
- Developers can now match
TAG
fields without needing to escape special characters, making the onboarding process and use of the query syntax simpler. - Geospatial search capabilities have been expanded with new
INTERSECT
andDISJOINT
operators, and ergonomics have been improved by providing better reporting of the memory consumed by the index and exposing the Full-text scoring in the aggregation pipeline.
Removal of triggers and functions
Redis Stack 7.4 will no longer include triggers and functions. To ensure a seamless upgrade, remove any T&F functions created before loading an RDB file into the new Redis Stack.
Details
Find more details about features and optimizations introduced with Redis Stack 7.4 here:
- Redis server
- Search and query capability
- JSON data structure
- Time series data structure
- Probabilistic data structures
Redis version
Module versions
Recommended client libraries
- Java
- Python
- NodeJS
- Go
Compatible with Redis Insight. The docker image redis/redis-stack for this version is bundled with Redis Insight 2.52.
Note: version numbers follow the pattern:
x.y.z-b
x.y
Redis Major versionz
increases with even numbers as a module x.y version increases.b
denotes a patch to Redis or a module (anyz
of Redis or modules).b
will consist of av
+ numeric value.