CVE-2026-97057 UNKNOWN

CVE-2026-97057

Published: 2026-09-24

Description

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a crafted RESP header with a length above 2^32-1 to crash the Node.js client process.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…