{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aredis-parser_projectredis-parsernode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redis-parser_project:redis-parser:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-97057"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["redis-parser (\u003c= 3.0.0)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","nodejs","library-vulnerability"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe redis-parser library, a component frequently used in Node.js applications for parsing the Redis Serialization Protocol (RESP), contains a critical validation flaw identified as CVE-2026-97057. The vulnerability exists because the library does not properly validate the multi-bulk length value during protocol parsing. An attacker who has compromised a Redis endpoint or is positioned as a malicious upstream Redis server can transmit a crafted RESP header with a length parameter exceeding 2^32-1. This payload causes the parser to trigger an uncaught RangeError within the JavaScript runtime, leading to an immediate process crash and denial of service. Because redis-parser is often a core dependency for Redis clients, this vulnerability directly impacts the availability of any Node.js service connecting to an untrusted or compromised Redis instance.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in an application-level denial of service for any Node.js process relying on redis-parser versions 3.0.0 or earlier. By forcing a process crash, attackers can disrupt backend services, queue consumers, or data caches that rely on Redis connectivity. Given the commonality of the redis-parser library in the Node.js ecosystem, widespread availability impact is possible for services integrated with external Redis clusters or Redis instances exposed to potentially malicious input.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit dependencies to identify all projects utilizing redis-parser versions 3.0.0 or lower.\u003c/li\u003e\n\u003cli\u003eUpgrade to a patched version of redis-parser that implements strict bounds checking on RESP length fields as soon as the vendor provides a resolution.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, implement ingress filtering or application-level sanity checks on the maximum expected size of RESP messages before passing them to the parser.\u003c/li\u003e\n\u003cli\u003eEnsure Redis clients are configured to connect only to authenticated and trusted Redis instances to mitigate the threat of a malicious or compromised upstream server.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-24T14:47:33Z","date_published":"2026-09-24T14:47:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-redis-parser-dos/","summary":"The redis-parser library up to version 3.0.0 fails to validate multi-bulk length values in the RESP protocol, allowing an attacker-controlled Redis endpoint to trigger an unhandled RangeError and crash the Node.js application process.","title":"Denial of Service Vulnerability in redis-parser via RESP Protocol","url":"https://feed.craftedsignal.io/briefs/2026-09-redis-parser-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:redis-Parser_project:redis-Parser:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}