Memetria Logo Memetria Changelog

You can now choose your data store’s eviction policy when creating a Memetria for Redis add-on on Heroku. For example, use noeviction for a queue that should reject writes when memory is full instead of evicting keys:

heroku addons:create memetria-redis:minidev -- --maxmemory-policy=noeviction

The setting applies from the first boot. You can also set maxmemory-policy in the add-on’s options in app.json for repeatable provisioning, including Review Apps. To change the policy afterward, use the Memetria dashboard.

You can now require encrypted connections when creating a Memetria for Redis add-on on Heroku:

heroku addons:create memetria-redis:minidev -- --tls-only

Plaintext connections are disabled from the first boot, and MEMETRIA_REDIS_URL contains a rediss:// URL. Your client must support TLS.

For repeatable provisioning, including Review Apps, set "tls-only": "true" in the add-on’s options in app.json.

Memetria’s Redis OSS 7.0 build now includes patches for four Lua scripting vulnerabilities: CVE-2025-49844, CVE-2025-46817, CVE-2025-46818, and CVE-2025-46819.

The fixes address potential remote code execution, execution in another user’s context, and an out-of-bounds read. These patches are backported to our Redis OSS 7.0 branch so customers can receive the fixes without changing major versions.

Valkey 7.2.11 is available on Memetria’s 7.2 branch.

This security release fixes four Lua scripting vulnerabilities: CVE-2025-49844, CVE-2025-46817, CVE-2025-46818, and CVE-2025-46819. These include potential remote code execution, execution in another user’s context, and an out-of-bounds read.

The release also fixes a crash involving empty Lua error tables and corrects client-tracking memory accounting.

Valkey 7.2.10 is available on Memetria’s 7.2 branch.

This release includes security fixes for HyperLogLog operations (CVE-2025-32023), connection handling (CVE-2025-48367), and the valkey-check-aof utility (CVE-2025-27151).

It also fixes crashes when establishing outbound TLS connections and improves client-pause and replication behavior.

Valkey 7.2.9 is available on Memetria’s 7.2 branch.

This release limits output buffers for unauthenticated clients to address CVE-2025-21605. It also includes fixes for TLS writes, stream consumer-group lag reporting, and several crash and memory-leak scenarios.

Valkey 7.2.8 is available on Memetria’s 7.2 branch.

This security and bugfix release addresses a potential remote code execution vulnerability in Lua scripting (CVE-2024-46981) and a denial-of-service vulnerability involving malformed ACL selectors (CVE-2024-51741).

It also fixes excess memory use with the inline protocol and improves command behavior for FUNCTION KILL and TOUCH.

We have updated Memetria’s Redis OSS builds on the 2.8, 3.0, 3.2, 4.0, 5.0, 6.0, 6.2, and 7.0 branches with security patches.

The update backports security fixes to these existing branches, including fixes for Lua scripting and denial-of-service vulnerabilities where applicable. Customers can receive these fixes without changing major versions.

As the latest (and future) releases of Redis are no longer open source, users who want to keep their data running on top of open source software face a choice: keep running on legacy Redis OSS, or upgrade to one of the more recent forks that the open source community has created.

Memetria will support both options.

We have been running builds of Valkey since that project was first announced as a fork created from the last open source release of Redis. The work already put into this project, and its forward momentum, are impressive.

Valkey 7.2 offers a clean, backwards-compatible upgrade path for users of Redis OSS to continue using the clients and features they enjoy while keeping a regular cadence of community-driven updates.

This upgrade path is now the main one supported by Memetria. All customers on our 7.2 branch are being seamlessly transitioned from data stores running Redis OSS 7.2 to Valkey 7.2 to ensure the latest security patches and bugfixes can be applied. Upgrades from earlier versions of Redis OSS are also supported.

We look forward to supporting similar zero-downtime upgrades to some of the exciting new features of Valkey soon.

Two new versions of open source Redis landed recently. 7.2.4 and 7.0.15 are security and bugfix releases only.

Memetria hosted databases on the 7.2 and 7.0 branches are being updated to the latest versions during their regular automated maintenance periods.