← All CVEs NewScan detects
high

CVE-2026-25589

Invalid memory access in RESTORE when used with the RedisBloom module -> potential remote code execution

Severity
high
Affected product
RedisBloom
Affected versions
RedisBloom ≥ 2.0.0, < 2.4.23
Affected versions
RedisBloom ≥ 2.6.0, < 2.6.28
Affected versions
RedisBloom ≥ 2.8.0, < 2.8.20
Fixed in
RedisBloom 2.4.23 / 2.6.28 / 2.8.20
Added to NewScan
2026-08-06
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints RedisBloom from its response and reports this CVE when the detected version falls inside the affected range below.

Module version comes from MODULE LIST on an unauthenticated instance (redis_recon decodes Redis' packed integer, e.g. 21010 -> 2.10.10). Ranges from the Redis module advisories.

COMPONENT VERSION RANGE

NewScan fingerprints RedisBloom from its response and reports this CVE when the detected version falls inside the affected range below.

Module version comes from MODULE LIST on an unauthenticated instance (redis_recon decodes Redis' packed integer, e.g. 21010 -> 2.10.10). Ranges from the Redis module advisories.

COMPONENT VERSION RANGE

NewScan fingerprints RedisBloom from its response and reports this CVE when the detected version falls inside the affected range below.

Module version comes from MODULE LIST on an unauthenticated instance (redis_recon decodes Redis' packed integer, e.g. 21010 -> 2.10.10). Ranges from the Redis module advisories.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →