Heap-based buffer overflow in RedisTimeSeries - CVE-2026-25588

 

Heap-based buffer overflow in RedisTimeSeries - CVE-2026-25588

Published: July 22, 2026


Vulnerability identifier: #VU139160
CSH Severity: Low
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25588
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in the RedisTimeSeries module when processing serialized values via the RESTORE command. A remote user can send a specially crafted serialized payload to execute arbitrary code.

Exploitation requires the RedisTimeSeries module to be loaded and permission to execute the RESTORE command.


Affected software

RedisTimeSeries
SecurityCenter

How to mitigate CVE-2026-25588

Install security update from vendor's website.

RedisTimeSeries - update to 1.12.14
SecurityCenter - addressed in versions SC202607.1, SC202607.2

External References

Related Security Bulletins