CVE-2026-93435: Noderedis Redis-Parser

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks.

Affected products

  • Noderedis Redis-Parser: up to and including 3.0.0

Published 2026-09-17. Last modified 2026-09-28.