CVE-2026-25588Disclosure(redistimeseries / redistimeseries)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch redistimeseries redistimeseries systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisTimeSeries module loaded can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This has been patched in version 1.12.14.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • redistimeseries

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 5d ago at 3 mentions (2026-05-07); latest day: 1
  • 11 total mentions across 8 days

Affected systems

Products
redistimeseries

Deep dive

Activity timeline11 mentions / 8d
01223Mentions · 2026-02-18: 1Mentions · 2026-05-05: 2Mentions · 2026-05-07: 3Mentions · 2026-05-20: 1Mentions · 2026-06-03: 1Mentions · 2026-06-07: 1Mentions · 2026-07-23: 1Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-07-23: 1Exploit Tool / Code · 2026-07-23: 1Patch / Workaround · 2026-05-05: 2Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-07-23: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-07: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-07: 1Technical Details · 2026-07-23: 102-1805-0505-0705-2006-0306-0707-2308-27
Signal classification4 categories
Disclosure
545.5%
General
327.3%
Patch
218.2%
Exploit
19.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-181
General1
2026-05-052
Disclosure1Patch1
2026-05-073
Disclosure1General1Patch1
2026-05-201
Disclosure1
2026-06-031
Disclosure1
2026-06-071
Disclosure1
2026-07-231
Exploit1
2026-08-271
General1
Full discourse11 posts
  • dbugs@ptdbugs
    Exploit

    Full-chain RCE exploit for RedisBloom (likely CVE-2026-25589) published. PT ID: PT-2026-37093 For informational purposes only. Type of vulnerability: Heap Buffer Overflow / Out-of-Bounds Read-Write → Authenticated RCE Affected component: RedisBloom, TDigest structure The vendor has reportedly published a full remote exploit for a vulnerability in RedisBloom. The attack is based on insufficient validation of serialized TDigest data when loaded via the RESTORE command. A specially crafted object causes an out-of-bounds write to the heap. The publication includes Python (exploit) and Bash (stand preparation) scripts. The reported vulnerability corresponds to CVE-2026-25589 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-37093). Redis disclosed the vulnerability -> (https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/) on May 5, 2026, stating that an authenticated user with permission to RESTORE could send a specially crafted payload, causing incorrect memory access and potentially achieving code execution within the Redis process. The vulnerability received a CVSS score of 7.7 according to Redis; NVD also lists a CVSS 3.1 score of 8.8. Patches were released in RedisBloom 2.8.20, 2.6.28, and 2.4.23, as well as in updated Redis OSS/CE branches. As a temporary measure, Redis recommends restricting the RESTORE privilege using ACLs. RedisBloom provides probabilistic data structures. The affected TDigest structure is used for approximate percentile and quantile calculations in data streams. Starting with Redis 8, probabilistic structures, including TDigest, are included in the standard Redis binary distributions. Redis -> (https://redis.io/tutorials/what-is-redis/) is a high-performance data store that primarily operates in memory. It is used as a NoSQL database, cache, session store, message broker, and task queue. Because it works with data in RAM, Redis provides low latency and is often used to accelerate high-traffic websites, APIs, and distributed applications. Redis Redis is widely used worldwide. According to the Stack Overflow Developer Survey 2025, 30.7% of professional developers worked with Redis in the past year, ranking fifth among the databases listed in the survey. #dbugs_darkweb

    Post summary

    Full-chain RCE exploit for RedisBloom’s TDigest RESTORE handling is disclosed with publicly available Python and Bash scripts, accompanied by detailed vulnerability metrics and patch information, but no evidence of active exploitation in the wild is presented.

    280522310.1K
    3.4K followersView on X
  • Xint@xint_official
    Disclosure

    CVE-2026-23479 in was one of the high severity bugs we found when we won at @wiz_io's ZeroDay Cloud competition. Be on the lookout soon for the technical deep dive on ZDC blog - this was a really interesting bug because of its subtlety. The complex interaction between portions of code far apart from each other in the codebase likely wouldn't have been noticed by humans or traditional SAST tools but can now be found in hours through AI with the right scaffolding Big thanks to the teams at @Redisinc and Wiz for the collaboration https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/

    Post summary

    The author announces the discovery of CVE-2026‑23479 during a ZeroDay Cloud competition, highlighting its subtle, high‑severity nature and noting an upcoming technical deep dive, but provides no PoC, exploitation evidence, patch, or detailed technical specifics.

    13032203.2K
    1.4K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    5 CVEs in Redis https://www.openwall.com/lists/oss-security/2026/06/03/18 CVE‑2026‑23479: Use-After-Free in unblock client flow may lead to Remote Code Execution CVE‑2026‑25243,CVE-2026-25588,CVE‑2026‑25589: Invalid Memory Access in RESTORE Command [...] May Lead to RCE CVE-2026-23631: Lua UAF may lead to RCE

    Post summary

    The message lists five newly disclosed Redis CVEs describing use‑after‑free and memory‑access flaws that could lead to remote code execution, but provides no PoC, exploit details, active exploitation evidence, or mitigation information.

    140841.5K
    4.7K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Redisで複数の深刻な脆弱性が修正。CVE-2026-23479、CVE-2026-25243、CVE-2026-25588、CVE-2026-25589のいずれもCVSSスコア7.7で、認証後ユーザによるメモリ破壊での遠隔コード実行。深刻度「中」の解放後メモリ使用CVE-2026-23631と併せ修正。 https://gbhackers.com/redis-security-flaws-expose-servers/

    Post summary

    Redis patched several CVEs (score 7.7, RCE post‑auth) and also addressed CVE‑2026‑23631; the article link offers additional technical details.

    030841.6K
    7.6K followersView on X
  • GoCocoaAI@GoCocoaAI
    Disclosure

    An autonomous AI tool just found what two years of human code review missed: a use-after-free in Redis that reaches all the way to remote code execution. CVE-2026-23479. CVSS 8.8. The flaw was introduced in Redis 7.2.0 — May 2023 — and lived undetected in every stable branch until it was patched in 8.6.3 on May 5, 2026. Two years of cloud caches, session stores, rate-limiters, and message queues running exploitable code. We are nothing if not consistent. The mechanics: the vulnerability lives in the unblock_client flow, specifically the error-handling path from processCommandAndResetClient. When a blocked client is evicted during re-execution, an authenticated attacker can trigger the use-after-free and land OS command execution on the server. It's exactly the kind of subtle memory-management edge case that slips through code review — the kind of thing that requires systematic automated reasoning to catch, not a second pair of human eyes on a PR. The PR:L requirement — low-privilege authentication — is the one thing keeping this from being a catastrophic internet-wide story right now. An attacker needs a valid Redis credential first. That bar is lower than it sounds. Redis credentials leak in public repos, .env files, and misconfigured cloud deployments with depressing regularity. Redis is on the honor system, apparently. A few things worth underscoring beyond the headline CVE: This was a batch remediation, not a single-bug patch. The Redis security advisory covers at least four CVEs in the same drop — CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, and CVE-2026-25589. If you're patching, patch the whole batch. No public PoC yet, no KEV listing, no confirmed wild exploitation — but that window is running. For a CVSS 8.8 RCE in a ubiquitous datastore, reconstructing the use-after-free from the patch diff is a standard adversarial workflow. Days to weeks, not months. The fact that an AI tool found it means the research community will want to reproduce it. That accelerates the timeline. Redis is the session and cache layer in a significant percentage of AI application backends — LLM inference pipelines, RAG stores, agent memory layers. Any deployment still running 7.2.0 through 8.6.2 should be treated as exposed until patched. The specific CVE matters. The broader signal matters more. Autonomous AI tools are now finding two-year-old critical flaws in production infrastructure at scale. Defenders using that capability find bugs before attackers do. Defenders not using it don't. That asymmetry is widening, and this is a proof point. CWE-416 — Use After Free | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N | Fixed: Redis 8.6.3

    Post summary

    An AI tool uncovered a use‑after‑free in Redis enabling remote code execution; the vulnerability (CVE‑2026‑23479) is patched in 8.6.3, with no exploitation yet reported.

    30000130
    16 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Redis ❗ CVE-2026-25589 ❗ CVE-2026-25588 ❗ CVE-2026-23479 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-redis/ https://t.co/YT4eMlEYZW

    Post summary

    The tweet announces three Redis CVEs and points to a link for additional information, but provides no further technical details.

    01010120
    6.7K followersView on X
  • Kovar@richardkovar
    General

    @Umesh__digital https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/

    Post summary

    The tweet shares only a link to a Redis security advisory covering multiple CVEs, providing no further details on exploitation, patches, or technical aspects.

    00000178
    508 followersView on X
  • Ashley@ashleykZA
    General

    4 High, and 1 Medium CVE in Redis https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/

    Post summary

    A brief note about four high‑severity and one medium‑severity CVEs in Redis, lacking PoC, exploit, patch, or technical detail.

    0000034
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25588 RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processe… https://www.cve.org/CVERecord?id=CVE-2026-25588 ----- Traducción: CVE-2026-25588 Red… http://infoflow.cloud`

    Post summary

    CVE-2026-25588 details an improper validation of serialized values in RedisTimeSeries before version 1.12.14, with the fix implied in that release.

    0000031
    75 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-25588 RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processe… https://www.cve.org/CVERecord?id=CVE-2026-25588

    Post summary

    CVE-2026-25588 exposes a validation flaw in RedisTimeSeries modules prior to version 1.12.14; the issue is addressed in that version.

    00000139
    57.4K followersView on X
  • DailyCVE@dailycve
    General

    🟠 OpenClaw, Authorization Bypass, #CVE-2026-25588 (Medium) https://dailycve.com/openclaw-authorization-bypass-cve-2026-25588-medium/

    Post summary

    The tweet merely announces CVE-2026-25588 – an authorization bypass in OpenClaw with medium severity – and links to an external article for details.

    0000030
    162 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredistimeseriesredistimeseries---

Explore more