Impact
The vulnerability exists in redis‑parser versions up to and including 3.0.0. The RESP protocol parser recurses unboundedly when it encounters a deeply nested array header in a crafted Redis byte stream. This eventual exhaustion of the V8 call stack triggers an uncaught RangeError that terminates the Node.js process. The library does not invoke error handling callbacks, so the client crashes without opportunity to recover or notify the application, resulting in a denial of service for the Node.js process.
Affected Systems
Clients that import the NodeRedis redis-parser library in Node.js environments are affected, provided they are using a version 3.0.0 or earlier. Any application that depends on this parser to interpret data from a Redis endpoint, whether local or remote, could be impacted if a malicious payload is received.
Risk and Exploitability
The CVSS score of 8.7 indicates significant severity, while the EPSS score of less than 1% implies that the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker who can cause the client to receive a malicious RESP payload from a Redis instance—either by compromising the Redis server or by engaging an otherwise trusted Redis endpoint that processes untrusted data. Once the nested arrays are received, the parser will recurse until the stack is exhausted, leading to a crash. The impact is limited to the client process but can cause application downtime if no monitoring or restart mechanism is in place.
OpenCVE Enrichment