Executive brief
RedisTimeSeries is a module for the Redis database used to manage and analyze time-stamped data. A security vulnerability in this module could allow an attacker with basic access to the database to execute malicious code on the server. This could lead to a complete system takeover, theft of sensitive data, or a total shutdown of the database service.
Technical details
A heap-based buffer overflow (CWE-122) exists in RedisTimeSeries due to insufficient validation of serialized values when processed via the Redis RESTORE command. An authenticated attacker with network access and permissions to execute the RESTORE command can provide a specially crafted serialized payload. This payload triggers invalid memory access, which can result in a crash (denial of service) or arbitrary remote code execution (RCE) in the context of the Redis server process. The vulnerability is patched in version 1.12.14; users unable to upgrade can mitigate the risk by using Redis ACLs to restrict access to the RESTORE command.
Affected products
- Redis RedisTimeSeries before 1.12.14
Timeline
- 2026-05-05: advisory: Vendor advisory and GitHub security advisory published
- 2026-05-05: patched: Version 1.12.14 released with security fixes
- 2026-05-05: disclosed