StackRadar

CVE-2026-25589

High

Advisory

Published 5 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.015
72nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 2
affected packages

RedisBloom RESTORE invalid memory access may allow remote code execution

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
redisdeb5:5.0.7-2ubuntu0.1, 5:7.0.15-1ubuntu0.24.04.1no fix listed3
redisbitnami8.0.2-1, 8.0.3-1, 8.2.1-0, 8.4.0-08.2.65
OSV records
BIT-redis-2026-25589UBUNTU-CVE-2026-25589
Also known as
BIT-keydb-2026-25589, GHSA-7862-34pw-44wv

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
weblateweblateOfficialVerified publisher0.5.361 of 3See more

weblate weblate 0.5.36

1 of the 3 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
bitnamilegacy/redis:latest5927ff3702df
redis@8.0.3-1
8.2.6

Open the chart page →

6,699
convoyconvoyVerified publisher3.7.131 of 3See more

convoy convoy 3.7.13

1 of the 3 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
redis@8.2.1-0
8.2.6

Open the chart page →

5,896
passboltpassbolt2.1.11 of 6See more

passbolt passbolt 2.1.1

1 of the 6 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
redis@8.2.1-0
8.2.6

Open the chart page →

13,350
infrahubinfrahubVerified publisher4.33.21 of 5See more

infrahub infrahub 4.33.2

1 of the 5 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
redis@8.2.1-0
8.2.6

Open the chart page →

10,428
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.19.21 of 5See more

infrahub-enterprise infrahub-enterprise 4.19.2

1 of the 5 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
redis@8.2.1-0
8.2.6

Open the chart page →

10,530
squestchristianhuthVerified publisher6.6.71 of 4See more

squest christianhuth 6.6.7

1 of the 4 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
redis@8.2.1-0
8.2.6

Open the chart page →

9,971
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
redis@8.2.1-0
8.2.6

Open the chart page →

7,473
arlas-aiasarlas-stackVerified publisher28.8.01 of 22See more

arlas-aias arlas-stack 28.8.0

1 of the 22 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
redis@8.0.3-1
8.2.6

Open the chart page →

40,238
rediscowboysysopVerified publisher21.2.61 of 1See more

redis cowboysysop 21.2.6

1 of the 1 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.0.2-debian-12-r4cdc2efa9c306
redis@8.0.2-1
8.2.6

Open the chart page →

2,621
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
redis@5:5.0.7-2ubuntu0.1
no fix listed

Open the chart page →

20,933
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
redis@5:7.0.15-1ubuntu0.24.04.1
no fix listed

Open the chart page →

8,967
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
bitnamilegacy/redis:latest5927ff3702df
redis@8.0.3-1
8.2.6

Open the chart page →

14,801
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
redis@5:5.0.7-2ubuntu0.1
no fix listed

Open the chart page →

30,687
rediswiremindVerified publisher23.0.61 of 1See more

redis wiremind 23.0.6

1 of the 1 container images this version deploys carry CVE-2026-25589.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
redis@8.4.0-0
8.2.6

Open the chart page →

2,113

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
redis@8.2.1-0
8.2.6
6
bitnamilegacy/redis:latest5927ff3702df
redis@8.0.3-1
8.2.6
2
arunvelsriram/utils:latest655ad18fd8d6
redis@5:7.0.15-1ubuntu0.24.04.1
no fix listed
1
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
redis@8.0.3-1
8.2.6
1
bitnamilegacy/redis:8.0.2-debian-12-r4cdc2efa9c306
redis@8.0.2-1
8.2.6
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
redis@5:5.0.7-2ubuntu0.1
no fix listed
1
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
redis@8.4.0-0
8.2.6
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
redis@5:5.0.7-2ubuntu0.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.