Integer overflow in RedisBloom - CVE-2026-62356
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to integer overflow in the RedisBloom CMSketch RDB loading logic when loading a specially crafted CMSketch object through RESTORE or a crafted RDB file. A remote user can load specially crafted serialized data to cause a denial of service or execute arbitrary code.