Loading market data...
← Back to CVE feed

CVE-2026-93435

HIGH CVSS 7.5 View on NVD ↗

Description

redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published: Sep 17, 2026 23:18 UTC Modified: Sep 17, 2026 23:18 UTC