Junglewise Threat Intelligence

CVE-2026-93435: redis-parser denial of service in RESP protocol parser

CVE-2026-93435 · Severity: high · CVSS 7.5 · Published 2026-09-17

Executive brief

redis-parser is a widely-used JavaScript library that parses the Redis protocol (RESP), used by Node.js applications to communicate with Redis servers. A malicious or compromised Redis endpoint can send specially crafted protocol messages that trigger unbounded recursion in the parser, causing the Node.js process to crash with an uncaught error and terminate immediately without proper cleanup or error handling.

Technical details

The vulnerability is a stack exhaustion / unbounded recursion flaw in the RESP protocol parser, specifically in the handling of nested array structures. When a Redis server sends a crafted byte stream with repeated array headers, the parser recursively processes the nesting without bounds, eventually exhausting the V8 JavaScript engine's call stack. This triggers a RangeError that is not caught by the application's error handlers, leading to an unhandled exception that crashes the entire Node.js process. The attack requires network connectivity to a Redis server (or a man-in-the-middle position on that connection), but does not require authentication or special client-side configuration. Patches are available in versions above 3.0.0.

Affected products

  • NodeRedis redis-parser through 3.0.0

Timeline

  • 2026-09-17: disclosed

References

Related threats