CVE-2024-55656
RedisBloom integer overflow via CMS.INITBYDIM with large WIDTH/DEPTH -> heap overflow, potential remote code execution
- Severity
- high
- Affected product
- RedisBloom
- Affected versions
- RedisBloom ≥ 2.0.0, < 2.4.13
- Affected versions
- RedisBloom ≥ 2.6.0, < 2.6.16
- Affected versions
- RedisBloom ≥ 2.8.0, < 2.8.5
- Fixed in
- RedisBloom 2.4.13 / 2.6.16 / 2.8.5
- Added to NewScan
- 2026-08-06
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints RedisBloom from its response and reports this CVE when the detected version falls inside the affected range below.
Module version comes from MODULE LIST on an unauthenticated instance (redis_recon decodes Redis' packed integer, e.g. 21010 -> 2.10.10). Ranges from the Redis module advisories.
COMPONENT VERSION RANGE
NewScan fingerprints RedisBloom from its response and reports this CVE when the detected version falls inside the affected range below.
Module version comes from MODULE LIST on an unauthenticated instance (redis_recon decodes Redis' packed integer, e.g. 21010 -> 2.10.10). Ranges from the Redis module advisories.
COMPONENT VERSION RANGE
NewScan fingerprints RedisBloom from its response and reports this CVE when the detected version falls inside the affected range below.
Module version comes from MODULE LIST on an unauthenticated instance (redis_recon decodes Redis' packed integer, e.g. 21010 -> 2.10.10). Ranges from the Redis module advisories.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →