{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/redis-parser--3.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redis:redis-parser:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-93435"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["redis-parser (\u003c= 3.0.0)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Redis"],"content_html":"\u003cp\u003eThe redis-parser library, widely used in the Node.js ecosystem, contains a critical denial of service (DoS) vulnerability in its RESP (REdis Serialization Protocol) parser, identified as CVE-2026-93435. The vulnerability exists in versions 3.0.0 and earlier and stems from improper handling of nested arrays within the protocol implementation.\u003c/p\u003e\n\u003cp\u003eAn attacker controlling a malicious Redis server, or capable of intercepting and modifying communication between a client and a legitimate Redis server, can transmit a crafted RESP byte stream. This stream contains deeply nested array headers that trigger unbounded recursion during parsing. This process exhausts the V8 call stack, leading to an unhandled RangeError. Because the error is not caught within the parser's logic, it propagates to the main execution context, forcing an immediate, ungraceful termination of the host Node.js process. This vulnerability is particularly impactful for high-availability applications that depend on stable Redis connections.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the immediate, unhandled crash of the application process using the vulnerable redis-parser library. This leads to a persistent denial of service condition for the affected service. The impact is significant for production environments where unexpected process termination can cause data loss, service outages, and secondary failures in dependent services that expect a continuous Redis connection.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all applications dependent on redis-parser to the latest version that includes the fix for CVE-2026-93435.\u003c/li\u003e\n\u003cli\u003eAudit dependencies using package management tools to identify and remove all instances of redis-parser versions 3.0.0 or lower.\u003c/li\u003e\n\u003cli\u003eMonitor application logs for Node.js process termination patterns (e.g., unexpected exit codes, stack trace overflows) that may indicate attempts to trigger this DoS vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T00:04:19Z","date_published":"2026-09-18T00:04:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-redis-parser-dos/","summary":"The redis-parser library up to version 3.0.0 is vulnerable to a denial of service attack where crafted RESP byte streams trigger unbounded recursion, exhausting the V8 call stack and crashing the host Node.js process.","title":"Denial of Service Vulnerability in redis-parser via RESP Recursion","url":"https://feed.craftedsignal.io/briefs/2026-09-redis-parser-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Redis-Parser (\u003c= 3.0.0)","version":"https://jsonfeed.org/version/1.1"}