Heap-based buffer overflow in RedisTimeSeries - CVE-2026-25588
Published: July 22, 2026
RedisTimeSeries
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in the RedisTimeSeries module when processing serialized values via the RESTORE command. A remote user can send a specially crafted serialized payload to execute arbitrary code.
Exploitation requires the RedisTimeSeries module to be loaded and permission to execute the RESTORE command.