PT-2026-20326 · Redis · Redistimeseries

Skateboarding Dog

·

Published

2026-02-18

·

Updated

2026-06-07

·

CVE-2026-25588

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RedisTimeSeries versions prior to 1.12.14
Description RedisTimeSeries, a time-series module for Redis, fails to properly validate serialized values processed through the 'RESTORE' command. An authenticated attacker with permissions to execute this command can provide a specially crafted serialized payload that triggers invalid memory access, specifically a heap buffer overflow. This may lead to remote code execution or a denial of service.
Recommendations Update to version 1.12.14. Restrict access to the 'RESTORE' command using ACL rules as a temporary workaround.

Exploit

Fix

RCE

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06449
BIT-KEYDB-2026-25588
BIT-REDIS-2026-25588
CVE-2026-25588
OPENSUSE-SU-2026:10711-1

Affected Products

Redistimeseries