Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-25589-25588-25243-23631-23479-REDIS β€” Diagnostic and remediation script for five Redis CVEs, providing scanning, ACL-based mitigation, and configuration hardening guidance for authenticated RCE vulnerabilities. | Kitploit
Tools/GitHubGitHub/mgiay/cve-2026-25589-25588-25243-23631-23479-redis
Vulnerability AnalysisConfiguration AuditingLearning & EducationCurated ResourcesDatabase Security
GitHubmgiay/cve-2026-25589-25588-25243-23631-23479-redis

CVE-2026-25589-25588-25243-23631-23479-REDIS

Diagnostic and remediation script for five Redis CVEs, providing scanning, ACL-based mitigation, and configuration hardening guidance for authenticated RCE vulnerabilities.

View Repository
365 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

GUIDE TO CHECKING & REMEDIATING 5 REDIS CVEs AS OF 2026.05.08

Release date: 2026-05-08 Author: TonyCao ([email protected]) Source: Redis Security Advisory


TABLE OF CONTENTS

  1. Overview
  2. Affected Versions
  3. Details of Each CVE
    • CVE-2026-23479 β€” Use-after-free in Unblock Client Flow
    • CVE-2026-25243 β€” Invalid Memory Access in RESTORE
    • CVE-2026-25588 β€” RESTORE with RedisTimeSeries Module
    • CVE-2026-25589 β€” RESTORE with RedisBloom Module
    • CVE-2026-23631 β€” Lua Use-After-Free via Master-Replica Sync
  4. Script Usage Guide
  5. Common Remediation Methods
  6. Risk Assessment β€” Internal Redis / Sentinel Systems
  7. ACL Reference
  8. Periodic Inspection Procedure
  9. Frequently Asked Questions (FAQ)

OVERVIEW

On 05/05/2026, Redis Ltd. published a security advisory about 5 critical security vulnerabilities affecting all Redis OSS/CE versions. All CVEs can lead to Remote Code Execution (RCE) if successfully exploited.

#CVE IDCVSSSeverityVulnerability TypeExploitation Conditions
1CVE-2026-234797.7HIGHUse-After-FreeAuthenticated, with permission to run blocking commands
2CVE-2026-252437.7HIGHInvalid Memory AccessAuthenticated, with permission to run RESTORE
3CVE-2026-255887.7HIGHInvalid Memory AccessAuthenticated, with RESTORE permission + RedisTimeSeries module
4CVE-2026-255897.7HIGHInvalid Memory AccessAuthenticated, with RESTORE permission + RedisBloom module
5CVE-2026-236316.1MEDIUMUse-After-FreeAuthenticated, replica with replica-read-only = disabled

Common point: All CVEs require the attacker to be authenticated to the Redis instance. CVE-2026-23631 only affects replicas with the replica-read-only disabled configuration.


AFFECTED VERSIONS

Redis OSS/CE β€” All versions prior to the patch

Version linePatched version (minimum)
6.2.x6.2.22
7.2.x7.2.14
7.4.x7.4.9
8.2.x8.2.6
8.4.x8.4.3
8.6.x8.6.3

Modules β€” Patched versions

ModuleMinimum version
RedisTimeSeries1.12.14 / 1.10.24 / 1.8.23
RedisBloom2.8.20 / 2.6.28 / 2.4.23

Redis Software (Enterprise)

VersionPatch
8.0.68.0.10-64
7.22.27.22.2-79
7.8.67.8.6-253
7.4.67.4.6-279
7.2.47.2.4-153

Redis Cloud

All Redis Cloud deployments have been automatically patched at the time of the advisory publication.


DETAILS OF EACH CVE

CVE-2026-23479

AttributeValue
TitleUse-After-Free in Unblock Client Flow
CVSS 4.07.7 (HIGH)
CWECWE-416 (Use After Free)
VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
ConditionAuthenticated attacker, with permission to execute blocking commands
ScopeAll Redis OSS/CE, Redis Software <= 8.0.6

Technical Description

When a blocked client β€” for example, one waiting in BLPOP β€” is evicted during the re-execution of the blocked command, the processCommandAndResetClient function may return an error. The current code does not handle this case correctly, leading to a pointer referencing already-freed memory (use-after-free). An attacker can exploit the UAF to execute remote code (RCE).

Indicators of Compromise

  • Redis server crash with a stack trace containing functions related to unblock client, processCommandAndResetClient
  • The redis-server process executing unidentified commands
  • Unauthorized network connections to the Redis instance

Affected Blocking Commands```

BLPOP, BRPOP, BRPOPLPUSH, BLMOVE, BLMPOP, BZPOPMIN, BZPOPMAX, BZMPOP, WAIT, WAITAOF, XREAD, XREADGROUP

#### Remediation method (without upgrading)

**Method 1 β€” Block via ACL (recommended):**```bash
# ChαΊ·n toΓ n bα»™ nhΓ³m lệnh blocking
redis-cli ACL SETUSER default -@blocking

# HoαΊ·c chαΊ·n tα»«ng lệnh cα»₯ thể
redis-cli ACL SETUSER default -BLPOP -BRPOP -BRPOPLPUSH -BLMOVE -BLMPOP \
                              -BZPOPMIN -BZPOPMAX -BZMPOP \
                              -WAIT -WAITAOF \
                              -XREAD -XREADGROUP

# LΖ°u ACL
redis-cli ACL SAVE

Method 2 β€” Disabling via rename-command (requires Redis restart):```bash

ThΓͺm vΓ o redis.conf:

rename-command BLPOP "" rename-command BRPOP "" rename-command BRPOPLPUSH "" rename-command BLMOVE "" rename-command BLMPOP "" rename-command BZPOPMIN "" rename-command BZPOPMAX "" rename-command BZMPOP "" rename-command WAIT "" rename-command WAITAOF "" rename-command XREAD "" rename-command XREADGROUP ""

**Method 3 β€” Enable protected-mode and limit connections:**```bash
redis-cli CONFIG SET protected-mode yes
# Trong redis.conf:
protected-mode yes
bind 127.0.0.1

CVE-2026-25243

AttributeValue
TitleInvalid Memory Access in RESTORE Command
CVSS 4.07.7 (HIGH)
CWECWE-20 (Improper Input Validation) + CWE-122 (Heap Buffer Overflow)
VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
ConditionAuthenticated attacker with RESTORE execution privileges
ScopeAll Redis OSS/CE, Redis Software <= 8.0.6

Technical Description

The vulnerability consists of 2 sub-issues:

  1. Double-free in Redis core (discovered by Emil Lerner) β€” RESTORE processes specially crafted serialized payloads leading to double memory release on the same pointer.
  2. Integer overflow and Out-Of-Bounds read in VectorSets (discovered by Joseph Surin) β€” specially crafted payloads cause integer overflow, leading to reads/writes outside the allocated memory region.

An authenticated attacker sends a specially crafted RESTORE payload to exploit the above flaws, potentially leading to RCE in the context of the redis-server process.

Indicators of Compromise

  • Unusual Redis server crash
  • Changes to system files (especially in the directory containing Redis RDB/AOF/config)
  • Unauthorized network connections to/from the Redis instance
  • Modified Redis configuration file

Mitigation Methods (without upgrading)

Method 1 β€” Block RESTORE via ACL (recommended):```bash

ChαΊ·n lệnh RESTORE

redis-cli ACL SETUSER default -restore

HoαΊ·c chαΊ·n toΓ n bα»™ nhΓ³m lệnh nguy hiểm

redis-cli ACL SETUSER default -@dangerous

Download Tool