Executive brief
RedisBloom is a module for the Redis database that provides advanced data structures for efficiently checking if items exist in a set. A security flaw allows an authorized user to send a specially crafted command that can crash the database or potentially allow them to take control of the server. This could lead to a total service outage, theft of sensitive data, or unauthorized access to the underlying infrastructure.
Technical details
A heap-based buffer overflow (CWE-122) exists in RedisBloom due to insufficient validation of serialized data processed via the Redis RESTORE command. An authenticated attacker with permissions to execute RESTORE can provide a malformed payload that triggers invalid memory access. This memory corruption can lead to a denial-of-service (crash) or arbitrary code execution in the context of the Redis server process. The vulnerability is reachable over the network if the attacker has valid credentials and the necessary ACL permissions. The issue is resolved in RedisBloom version 2.8.20; a recommended workaround is to restrict access to the RESTORE command using Redis ACL rules.
Affected products
- Redis RedisBloom All versions before 2.8.20
Timeline
- 2026-05-05: disclosed
- 2026-05-05: advisory
- 2026-05-05: patched: Fixed in version 2.8.20