go-redis is generally backward compatible with very few exceptions, so we recommend users to always use the latest version to experience stability, performance and security. Security fixes are released as part of the latest release of the v9 line; older major versions are no longer maintained.
If you believe you have found a security vulnerability, to ensure proper review and assessment, we kindly ask vulnerability reports be submitted through our Redis Vulnerability Disclosure Program. Alternatively reach out via email to security@redis.com.
Please do not report security vulnerabilities through public GitHub issues.