CVE-2026-25589Disclosure(redisbloom / redisbloom)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch redisbloom redisbloom systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisBloom module loaded can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This issue is fixed in version 2.8.20.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • redisbloom

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 2 mentions (2026-05-05); latest day: 1
  • 9 total mentions across 8 days

Affected systems

Vendors
Products
redisbloom

Deep dive

Activity timeline9 mentions / 8d
01122Mentions · 2026-05-05: 2Mentions · 2026-05-20: 1Mentions · 2026-06-03: 1Mentions · 2026-07-23: 1Mentions · 2026-07-27: 1Mentions · 2026-07-30: 1Mentions · 2026-07-31: 1Mentions · 2026-08-29: 1PoC Mentioned / Linked · 2026-07-23: 1PoC Mentioned / Linked · 2026-07-27: 1PoC Mentioned / Linked · 2026-07-31: 1Exploit Tool / Code · 2026-07-23: 1Exploit Tool / Code · 2026-07-27: 1Exploit Tool / Code · 2026-07-31: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-07-23: 1Patch / Workaround · 2026-07-30: 1Patch / Workaround · 2026-07-31: 1Technical Details · 2026-05-05: 2Technical Details · 2026-06-03: 1Technical Details · 2026-07-23: 1Technical Details · 2026-07-27: 1Technical Details · 2026-07-30: 1Technical Details · 2026-07-31: 105-0505-2006-0307-2307-2707-3007-3108-29
Signal classification5 categories
Disclosure
333.3%
General
222.2%
Exploit
222.2%
Patch
111.1%
PoC
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure1Patch1
2026-05-201
General1
2026-06-031
Disclosure1
2026-07-231
Exploit1
2026-07-271
PoC1
2026-07-301
Disclosure1
2026-07-311
Exploit1
2026-08-291
General1
Full discourse9 posts
  • dbugs@ptdbugs
    Exploit

    Full-chain RCE exploit for RedisBloom (likely CVE-2026-25589) published. PT ID: PT-2026-37093 For informational purposes only. Type of vulnerability: Heap Buffer Overflow / Out-of-Bounds Read-Write → Authenticated RCE Affected component: RedisBloom, TDigest structure The vendor has reportedly published a full remote exploit for a vulnerability in RedisBloom. The attack is based on insufficient validation of serialized TDigest data when loaded via the RESTORE command. A specially crafted object causes an out-of-bounds write to the heap. The publication includes Python (exploit) and Bash (stand preparation) scripts. The reported vulnerability corresponds to CVE-2026-25589 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-37093). Redis disclosed the vulnerability -> (https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/) on May 5, 2026, stating that an authenticated user with permission to RESTORE could send a specially crafted payload, causing incorrect memory access and potentially achieving code execution within the Redis process. The vulnerability received a CVSS score of 7.7 according to Redis; NVD also lists a CVSS 3.1 score of 8.8. Patches were released in RedisBloom 2.8.20, 2.6.28, and 2.4.23, as well as in updated Redis OSS/CE branches. As a temporary measure, Redis recommends restricting the RESTORE privilege using ACLs. RedisBloom provides probabilistic data structures. The affected TDigest structure is used for approximate percentile and quantile calculations in data streams. Starting with Redis 8, probabilistic structures, including TDigest, are included in the standard Redis binary distributions. Redis -> (https://redis.io/tutorials/what-is-redis/) is a high-performance data store that primarily operates in memory. It is used as a NoSQL database, cache, session store, message broker, and task queue. Because it works with data in RAM, Redis provides low latency and is often used to accelerate high-traffic websites, APIs, and distributed applications. Redis Redis is widely used worldwide. According to the Stack Overflow Developer Survey 2025, 30.7% of professional developers worked with Redis in the past year, ranking fifth among the databases listed in the survey. #dbugs_darkweb

    Post summary

    The publication details a full RCE exploit for RedisBloom (CVE-2026-25589) with PoC Python and Bash scripts, while also providing patch information and mitigation recommendations.

    280522310.1K
    3.4K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    Discover how new Redis RCE exploit PoC code bypasses fixes for CVE-2026-25243 and CVE-2026-25589 across multiple Redis versions. #Redis #Cybersecurity #RCE #Vulnerability #ExploitPoC http://meterpreter.org/redis-rce-exploit-poc/

    Post summary

    The post announces a new Redis RCE PoC that bypasses fixes for CVE-2026-25243 and CVE-2026-25589, providing a link to the exploit code.

    050191871
    13.0K followersView on X
  • GoCocoaAI@GoCocoaAI
    Disclosure

    An autonomous AI tool just found what two years of human code review missed: a use-after-free in Redis that reaches all the way to remote code execution. CVE-2026-23479. CVSS 8.8. The flaw was introduced in Redis 7.2.0 — May 2023 — and lived undetected in every stable branch until it was patched in 8.6.3 on May 5, 2026. Two years of cloud caches, session stores, rate-limiters, and message queues running exploitable code. We are nothing if not consistent. The mechanics: the vulnerability lives in the unblock_client flow, specifically the error-handling path from processCommandAndResetClient. When a blocked client is evicted during re-execution, an authenticated attacker can trigger the use-after-free and land OS command execution on the server. It's exactly the kind of subtle memory-management edge case that slips through code review — the kind of thing that requires systematic automated reasoning to catch, not a second pair of human eyes on a PR. The PR:L requirement — low-privilege authentication — is the one thing keeping this from being a catastrophic internet-wide story right now. An attacker needs a valid Redis credential first. That bar is lower than it sounds. Redis credentials leak in public repos, .env files, and misconfigured cloud deployments with depressing regularity. Redis is on the honor system, apparently. A few things worth underscoring beyond the headline CVE: This was a batch remediation, not a single-bug patch. The Redis security advisory covers at least four CVEs in the same drop — CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, and CVE-2026-25589. If you're patching, patch the whole batch. No public PoC yet, no KEV listing, no confirmed wild exploitation — but that window is running. For a CVSS 8.8 RCE in a ubiquitous datastore, reconstructing the use-after-free from the patch diff is a standard adversarial workflow. Days to weeks, not months. The fact that an AI tool found it means the research community will want to reproduce it. That accelerates the timeline. Redis is the session and cache layer in a significant percentage of AI application backends — LLM inference pipelines, RAG stores, agent memory layers. Any deployment still running 7.2.0 through 8.6.2 should be treated as exposed until patched. The specific CVE matters. The broader signal matters more. Autonomous AI tools are now finding two-year-old critical flaws in production infrastructure at scale. Defenders using that capability find bugs before attackers do. Defenders not using it don't. That asymmetry is widening, and this is a proof point. CWE-416 — Use After Free | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N | Fixed: Redis 8.6.3

    Post summary

    An AI tool uncovered a use‑after‑free flaw in Redis that enables remote code execution; the vulnerability is documented with a CVSS of 8.8 and has been patched in newer releases. No exploit or active exploitation has been reported yet.

    30000130
    16 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Redis ❗ CVE-2026-25589 ❗ CVE-2026-25588 ❗ CVE-2026-23479 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-redis/ https://t.co/YT4eMlEYZW

    Post summary

    The tweet simply lists three Redis CVE identifiers and points to a link for more information, offering no technical or operational details.

    01010120
    6.7K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Redis Server で発見された脆弱性の悪用経路:Kimi K3 AI Agent が問題点を検出 https://iototsecnews.jp/2026/07/23/new-kimi-k3-ai-agent-uncovers-0-day-exploits-in-redis-server/ インメモリ・データストアである Redis において、特定の処理や拡張機能の不具合によりメモリ構造が崩れ、認証を得た第三者に不正な指令を実行される脆弱性 CVE-2026-25589 が公表されました。この脆弱性の発見に貢献したのは、Kimi K3 AI エージェントです。権限を持つ利用者の情報が第三者に渡り、この脆弱性が悪用されると、端末の操作権を奪われる危険性が生じます。安全に利用するためにも、公式に提供される修正プログラムを追跡して迅速に導入し、不要なコマンドの利用制限やネットワークの適切な隔離などを実施する必要があります。 #CVE202625589 #KimiK3AIAgent #Redis #Vulnerability

    Post summary

    The article reports the public disclosure of a memory‑corruption CVE-2026-25589 in Redis, discovered by Kimi K3 AI Agent, and urges prompt patching.

    01000179
    503 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-25589: RedisBloom Module Memory Corruption Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04vNlxJ0

    Post summary

    The article announces a memory corruption bug in the RedisBloom module (CVE-2026-25589) but provides no concrete technical, exploit, or patch details.

    0000041
    36 followersView on X
  • S2W_DailyThreat@S2W_DailyThreat
    Exploit

    [VULNERABILITY] RedisBloom (CVE-2026-25589): Code-execution flaw now has public exploit. Target Version: RedisBloom 2.4.x < 2.4.23, RedisBloom 2.6.x < 2.6.28, RedisBloom 2.8.x < 2.8.20 CVE-2026-25589, disclosed on 2026 May 5, is an arbitrary code execution flaw in RedisBloom's RESTORE command handling, with a CVSS 3.1 score of 8.8 (HIGH). It stems from insufficient validation of serialized payloads. ✔ An authenticated attacker with RESTORE privileges can submit a crafted serialized payload. RedisBloom deserializes the payload without adequate validation, leading to out-of-bounds memory access and potential code execution within the Redis server process context — potentially enabling server takeover. On 2026 July 23, a Git repository containing a PoC was shared on X. Combined with additional flaws, the exploit chain can escalate the impact to remote code execution, lowering the barrier to exploitation. 📌 S2W Advisory: Apply the vendor security update immediately. If immediate patching is not possible, restrict RESTORE access to trusted administrators via ACL, firewall Redis ports to trusted clients, bind Redis only to trusted interfaces, and run redis-server under a non-privileged OS account. Follow @S2W_DailyThreat #Vulnerability #RedisBloom #S2W

    Post summary

    RedisBloom CVE‑2026‑25589, a high‑severity RCE flaw, now has a publicly shared exploit repository, and vendors urge immediate patching or mitigation.

    00000280
    151 followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-25589 RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values p… https://www.cve.org/CVERecord?id=CVE-2026-25589 ----- Traducción: CVE-2026-25589 Red… http://infoflow.cloud`

    Post summary

    CVE‑2026‑25589 affects RedisBloom versions prior to 2.8.20 due to improper validation of serialized values, and upgrading to 2.8.20 or later mitigates the vulnerability.

    0000029
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25589 RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values p… https://www.cve.org/CVERecord?id=CVE-2026-25589

    Post summary

    CVE-2026-25589 is a vulnerability in RedisBloom where serialized values lack proper validation in versions prior to 2.8.20, with no evidence of PoC, exploitation, patch, or debunking.

    00000136
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredisbloomredisbloom---

Explore more