
Diagnostic and remediation script for five Redis CVEs, providing scanning, ACL-based mitigation, and configuration hardening guidance for authenticated RCE vulnerabilities.
Release date: 2026-05-08 Author: TonyCao ([email protected]) Source: Redis Security Advisory
On 05/05/2026, Redis Ltd. published a security advisory about 5 critical security vulnerabilities affecting all Redis OSS/CE versions. All CVEs can lead to Remote Code Execution (RCE) if successfully exploited.
| # | CVE ID | CVSS | Severity | Vulnerability Type | Exploitation Conditions |
|---|---|---|---|---|---|
| 1 | CVE-2026-23479 | 7.7 | HIGH | Use-After-Free | Authenticated, with permission to run blocking commands |
| 2 | CVE-2026-25243 | 7.7 | HIGH | Invalid Memory Access | Authenticated, with permission to run RESTORE |
| 3 | CVE-2026-25588 | 7.7 | HIGH | Invalid Memory Access | Authenticated, with RESTORE permission + RedisTimeSeries module |
| 4 | CVE-2026-25589 | 7.7 | HIGH | Invalid Memory Access | Authenticated, with RESTORE permission + RedisBloom module |
| 5 | CVE-2026-23631 | 6.1 | MEDIUM | Use-After-Free | Authenticated, replica with replica-read-only = disabled |
Common point: All CVEs require the attacker to be authenticated to the Redis instance. CVE-2026-23631 only affects replicas with the
replica-read-only disabledconfiguration.
| Version line | Patched version (minimum) |
|---|---|
| 6.2.x | 6.2.22 |
| 7.2.x | 7.2.14 |
| 7.4.x | 7.4.9 |
| 8.2.x | 8.2.6 |
| 8.4.x | 8.4.3 |
| 8.6.x | 8.6.3 |
| Module | Minimum version |
|---|---|
| RedisTimeSeries | 1.12.14 / 1.10.24 / 1.8.23 |
| RedisBloom | 2.8.20 / 2.6.28 / 2.4.23 |
| Version | Patch |
|---|---|
| 8.0.6 | 8.0.10-64 |
| 7.22.2 | 7.22.2-79 |
| 7.8.6 | 7.8.6-253 |
| 7.4.6 | 7.4.6-279 |
| 7.2.4 | 7.2.4-153 |
All Redis Cloud deployments have been automatically patched at the time of the advisory publication.
| Attribute | Value |
|---|---|
| Title | Use-After-Free in Unblock Client Flow |
| CVSS 4.0 | 7.7 (HIGH) |
| CWE | CWE-416 (Use After Free) |
| Vector | AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Condition | Authenticated attacker, with permission to execute blocking commands |
| Scope | All Redis OSS/CE, Redis Software <= 8.0.6 |
When a blocked client β for example, one waiting in BLPOP β is evicted during the re-execution of the blocked command, the processCommandAndResetClient function may return an error. The current code does not handle this case correctly, leading to a pointer referencing already-freed memory (use-after-free). An attacker can exploit the UAF to execute remote code (RCE).
unblock client, processCommandAndResetClientredis-server process executing unidentified commandsBLPOP, BRPOP, BRPOPLPUSH, BLMOVE, BLMPOP, BZPOPMIN, BZPOPMAX, BZMPOP, WAIT, WAITAOF, XREAD, XREADGROUP
#### Remediation method (without upgrading)
**Method 1 β Block via ACL (recommended):**```bash
# ChαΊ·n toΓ n bα» nhΓ³m lα»nh blocking
redis-cli ACL SETUSER default -@blocking
# HoαΊ·c chαΊ·n tα»«ng lα»nh cα»₯ thα»
redis-cli ACL SETUSER default -BLPOP -BRPOP -BRPOPLPUSH -BLMOVE -BLMPOP \
-BZPOPMIN -BZPOPMAX -BZMPOP \
-WAIT -WAITAOF \
-XREAD -XREADGROUP
# LΖ°u ACL
redis-cli ACL SAVE
Method 2 β Disabling via rename-command (requires Redis restart):```bash
rename-command BLPOP "" rename-command BRPOP "" rename-command BRPOPLPUSH "" rename-command BLMOVE "" rename-command BLMPOP "" rename-command BZPOPMIN "" rename-command BZPOPMAX "" rename-command BZMPOP "" rename-command WAIT "" rename-command WAITAOF "" rename-command XREAD "" rename-command XREADGROUP ""
**Method 3 β Enable protected-mode and limit connections:**```bash
redis-cli CONFIG SET protected-mode yes
# Trong redis.conf:
protected-mode yes
bind 127.0.0.1
| Attribute | Value |
|---|---|
| Title | Invalid Memory Access in RESTORE Command |
| CVSS 4.0 | 7.7 (HIGH) |
| CWE | CWE-20 (Improper Input Validation) + CWE-122 (Heap Buffer Overflow) |
| Vector | AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Condition | Authenticated attacker with RESTORE execution privileges |
| Scope | All Redis OSS/CE, Redis Software <= 8.0.6 |
The vulnerability consists of 2 sub-issues:
An authenticated attacker sends a specially crafted RESTORE payload to exploit the above flaws, potentially leading to RCE in the context of the redis-server process.
Method 1 β Block RESTORE via ACL (recommended):```bash
redis-cli ACL SETUSER default -restore
redis-cli ACL SETUSER default -@dangerous