Description
redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability exists in redis‑parser versions up to and including 3.0.0. The RESP protocol parser recurses unboundedly when it encounters a deeply nested array header in a crafted Redis byte stream. This eventual exhaustion of the V8 call stack triggers an uncaught RangeError that terminates the Node.js process. The library does not invoke error handling callbacks, so the client crashes without opportunity to recover or notify the application, resulting in a denial of service for the Node.js process.

Affected Systems

Clients that import the NodeRedis redis-parser library in Node.js environments are affected, provided they are using a version 3.0.0 or earlier. Any application that depends on this parser to interpret data from a Redis endpoint, whether local or remote, could be impacted if a malicious payload is received.

Risk and Exploitability

The CVSS score of 8.7 indicates significant severity, while the EPSS score of less than 1% implies that the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker who can cause the client to receive a malicious RESP payload from a Redis instance—either by compromising the Redis server or by engaging an otherwise trusted Redis endpoint that processes untrusted data. Once the nested arrays are received, the parser will recurse until the stack is exhausted, leading to a crash. The impact is limited to the client process but can cause application downtime if no monitoring or restart mechanism is in place.

Generated by OpenCVE AI on September 19, 2026 at 12:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the NodeRedis redis-parser library to a fixed version, if available, that resolves the unbounded recursion issue.
  • If an immediate upgrade is not possible, restrict communication to trusted Redis instances and implement server‑side validation to reject or sanitize deeply nested array payloads that could trigger recursion.
  • Deploy a process supervisor or watchdog that can detect a Node.js crash and automatically restart the application to minimize downtime.

Generated by OpenCVE AI on September 19, 2026 at 12:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
References

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Noderedis
Noderedis redis-parser
Vendors & Products Noderedis
Noderedis redis-parser

Thu, 17 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks.
Title redis-parser through 3.0.0 Denial of Service via Unbounded Recursion
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Noderedis Redis-parser
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T14:35:35.359Z

Reserved: 2026-09-17T21:49:06.579Z

Link: CVE-2026-93435

cve-icon Vulnrichment

Updated: 2026-09-21T14:58:23.576Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T23:18:54.553

Modified: 2026-09-28T15:17:24.730

Link: CVE-2026-93435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T12:30:17Z

Weaknesses