Loading market data...
← Back to CVE feed

CVE-2026-97057

HIGH CVSS 7.5 View on NVD ↗

Description

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a crafted RESP header with a length above 2^32-1 to crash the Node.js client process.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published: Sep 24, 2026 14:18 UTC Modified: Sep 24, 2026 21:08 UTC