Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-97057

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Sep 24, 2026
Vendor unknown

Description

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a crafted RESP header with a length above 2^32-1 to crash the Node.js client process.

References