- Description
- RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisTimeSeries module loaded can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This has been patched in version 1.12.14.
- Source
- security-advisories@github.com
- NVD status
- Undergoing Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 7.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- security-advisories@github.com
- CWE-122
- Hype score
- Not currently trending
5 CVEs in Redis https://t.co/32ZcxyrYW5 CVE‑2026‑23479: Use-After-Free in unblock client flow may lead to Remote Code Execution CVE‑2026‑25243,CVE-2026-25588,CVE‑2026‑25589: Invalid Memory Access in RESTORE Command [...] May Lead to RCE CVE-2026-23631: Lua UAF may lea
@oss_security
7 Jun 2026
1262 Impressions
4 Retweets
7 Likes
4 Bookmarks
1 Reply
0 Quotes
⚠️ Vulnerabilidades en productos Redis ❗ CVE-2026-25589 ❗ CVE-2026-25588 ❗ CVE-2026-23479 ➡️ Más info: https://t.co/3dKb2iYiAZ https://t.co/YT4eMlEYZW
@CERTpy
20 May 2026
94 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes