OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97057

HIGH · CVSS 7.5 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The redis-parser library, up to version 3.0.0, is vulnerable due to inadequate validation of multi-bulk length values in RESP protocol parsing, which can lead to a RangeError when an attacker supplies a maliciously large length value. This vulnerability can cause the Node.js client process to crash, potentially disrupting services that rely on Redis. Organizations using affected versions of redis-parser should prioritize patching to mitigate the risk of service interruptions and potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-97057
Severity
HIGH
CVSS
7.5
EPSS
0.39%

Original NVD Description

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a crafted RESP header with a length above 2^32-1 to crash the Node.js client process.