← All CVEs NewScan detects
high

CVE-2024-55656

RedisBloom integer overflow via CMS.INITBYDIM with large WIDTH/DEPTH -> heap overflow, potential remote code execution

Severity
high
Affected product
RedisBloom
Affected versions
RedisBloom ≥ 2.0.0, < 2.4.13
Affected versions
RedisBloom ≥ 2.6.0, < 2.6.16
Affected versions
RedisBloom ≥ 2.8.0, < 2.8.5
Fixed in
RedisBloom 2.4.13 / 2.6.16 / 2.8.5
Added to NewScan
2026-08-06
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints RedisBloom from its response and reports this CVE when the detected version falls inside the affected range below.

Module version comes from MODULE LIST on an unauthenticated instance (redis_recon decodes Redis' packed integer, e.g. 21010 -> 2.10.10). Ranges from the Redis module advisories.

COMPONENT VERSION RANGE

NewScan fingerprints RedisBloom from its response and reports this CVE when the detected version falls inside the affected range below.

Module version comes from MODULE LIST on an unauthenticated instance (redis_recon decodes Redis' packed integer, e.g. 21010 -> 2.10.10). Ranges from the Redis module advisories.

COMPONENT VERSION RANGE

NewScan fingerprints RedisBloom from its response and reports this CVE when the detected version falls inside the affected range below.

Module version comes from MODULE LIST on an unauthenticated instance (redis_recon decodes Redis' packed integer, e.g. 21010 -> 2.10.10). Ranges from the Redis module advisories.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →