CyberRota Analysis
AI-GeneratedThe redis-parser library, up to version 3.0.0, is vulnerable due to inadequate validation of multi-bulk length values in RESP protocol parsing, which can lead to a RangeError when an attacker supplies a maliciously large length value. This vulnerability can cause the Node.js client process to crash, potentially disrupting services that rely on Redis. Organizations using affected versions of redis-parser should prioritize patching to mitigate the risk of service interruptions and potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a crafted RESP header with a length above 2^32-1 to crash the Node.js client process.