Skip to content

Menu
  • Home
Menu

CVE-2026-93435 – redis-parser through 3.0.0 Denial of Service via Unbounded Recursion

Posted on September 18, 2026
CVE ID :CVE-2026-93435

Published : Sept. 17, 2026, 11:18 p.m. | 16 minutes ago

Description :redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks.

Severity: 8.7 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Post Views: 3

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme