https://seclists.org/oss-sec/2026/q2/804: 5 CVEs in dis
Published Jun 3, 2026
·Updated
Affected Software
3 affected components
Redis Redis OSS/CE<6.2.22, <7.2.14, <7.4.9, <8.2.6, <8.4.3, <8.6.3
Redis RedisTimeSeries<1.12.14, <1.10.24, <1.8.23
Redis RedisBloom<2.8.20, <2.6.28, <2.4.23
Frequently Asked Questions
1
What is the severity of CVE-2026-23479?
CVE-2026-23479 has been rated as high severity due to potential data exposure vulnerabilities.
2
How do I fix CVE-2026-23479?
To fix CVE-2026-23479, update your Redis installation to the latest version as recommended in the security advisory.
3
What vulnerabilities are associated with CVE-2026-25243?
CVE-2026-25243 involves an insecure configuration issue that can lead to unintended data access.
4
Is there a patch available for CVE-2026-25588?
Yes, a patch for CVE-2026-25588 is included in the latest Redis release, so users should upgrade accordingly.
5
What products are affected by the CVEs listed in the Redis advisory?
The vulnerabilities affect Redis OSS/CE, RedisTimeSeries, and RedisBloom.