redis-parser through 3.0.0 Denial of Service via Invalid Array Length
Published Sep 24, 2026
8.7
HIGHCVSS 4.0
EPSS 0.39%
Description
redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a crafted RESP header with a length above 2^32-1 to crash the Node.js client process.
Affected products
-
- Version 0StatusaffectedConstraints<=3.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| NodeRedis | Redis-Parser | unaffected |
|
No data.
No data.
Red Hat Developer Hub
rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend
Affected
Red Hat Developer Hub
rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend
Affected
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Affected
Red Hat Fuse 7
redis-parser
Will not fix
Red Hat Satellite 6
satellite/iop-remediations-rhel9
Affected
Self-service automation portal 2
ansible-automation-platform/automation-portal
Affected
Self-service automation portal 2
ansible-automation-platform/bootc-automation-portal-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Developer Hub | rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend | Affected | n/a |
| Red Hat Developer Hub | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend | Affected | n/a |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Affected | n/a |
| Red Hat Fuse 7 | redis-parser | Will not fix | n/a |
| Red Hat Satellite 6 | satellite/iop-remediations-rhel9 | Affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/automation-portal | Affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/bootc-automation-portal-rhel9 | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2026-97057 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2540095 Issue Tracking
- https://github.com/NodeRedis/node-redis-parser product
- https://github.com/NodeRedis/node-redis-parser/blob/4c2d31c8717f05dea1ffd91a0e45d68f452c73bd/lib/parser.js#L108-L122 technical-description
- https://github.com/NodeRedis/node-redis-parser/blob/4c2d31c8717f05dea1ffd91a0e45d68f452c73bd/lib/parser.js#L212 technical-description
- https://github.com/NodeRedis/node-redis-parser/blob/4c2d31c8717f05dea1ffd91a0e45d68f452c73bd/lib/parser.js#L492-L550 technical-description
- https://github.com/NodeRedis/node-redis-parser/issues/47 issue-tracking
- https://github.com/NodeRedis/node-redis-parser/issues/65 issue-tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-97057
- https://www.cve.org/CVERecord?id=CVE-2026-97057
- https://www.vulncheck.com/advisories/redis-parser-through-3.0.0-denial-of-service-via-invalid-array-length third-party-advisory
Change history (0)
No recorded changes yet.