A lot — Redis is single threaded, so KEYS blocks every other client for the whole scan. At 8 million keys that is comfortably into multi-second territory, and everything else queues behind it.
Use SCAN, which returns a cursor and does bounded work per call:
Note UNLINK rather than DEL — it frees memory on a background thread instead of blocking.
Better still, don't scan at all: set a TTL when you create the session and let Redis expire them for you.