Remote Code Execution Vulnerability in RedisBloom by Redis
CVE-2026-25589
7.7HIGH
What is CVE-2026-25589?
RedisBloom, a probabilistic data structures module for Redis, has a vulnerability that allows an authenticated attacker to exploit improper validation of serialized values processed via the RESTORE command. This flaw can lead to invalid memory access and may enable remote code execution. To mitigate this risk, users are advised to implement access control through ACL rules, limiting access to the RESTORE command. The vulnerability has been addressed in version 2.8.20.
Affected Version(s)
RedisBloom < 2.8.20
