Heap-based buffer overflow in RedisBloom - CVE-2026-25589

 

Heap-based buffer overflow in RedisBloom - CVE-2026-25589

Published: July 22, 2026


Vulnerability identifier: #VU139161
CSH Severity: Low
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25589
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in the Redis RESTORE command handling within the RedisBloom module when processing a specially crafted serialized payload. A remote user can send a specially crafted serialized payload to execute arbitrary code.

Exploitation requires the RedisBloom module to be loaded and permission to execute the RESTORE command.


Affected software

RedisBloom
SecurityCenter

How to mitigate CVE-2026-25589

Install security update from vendor's website.

RedisBloom - update to 2.8.20
SecurityCenter - addressed in versions SC202607.1, SC202607.2

External References

Related Security Bulletins