Remote Code Execution Vulnerability in RedisBloom by Redis
CVE-2026-25589

7.7HIGH

Key Information:

Vendor

Redisbloom

Vendor
CVE Published:
5 May 2026

What is CVE-2026-25589?

RedisBloom, a probabilistic data structures module for Redis, has a vulnerability that allows an authenticated attacker to exploit improper validation of serialized values processed via the RESTORE command. This flaw can lead to invalid memory access and may enable remote code execution. To mitigate this risk, users are advised to implement access control through ACL rules, limiting access to the RESTORE command. The vulnerability has been addressed in version 2.8.20.

Affected Version(s)

RedisBloom < 2.8.20

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.