CPE
The redis-parser library up to version 3.0.0 fails to validate multi-bulk length values in the RESP protocol, allowing an attacker-controlled Redis endpoint to trigger an unhandled RangeError and crash the Node.js application process.