Bug 2540095 (CVE-2026-97057)

Summary: CVE-2026-97057 redis-parser: redis-parser: Denial of Service via invalid RESP protocol array length
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abarbaro, alizardo, anthomas, dschmidt, ehelms, ggainey, gmalinko, janstey, jchui, jhe, jlanda, jpasqual, juwatts, kshier, ktsao, mdellweg, mhulan, mstipich, nboldt, nmoumoul, oaljalju, osousa, pcreech, pdelbell, psrna, rchan, rexwhite, rstepani, simaishi, smallamp, stcannon, sthirugn, tmalecek, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in redis-parser. This vulnerability allows a malicious or compromised Redis endpoint to trigger an uncaught RangeError by sending a crafted RESP (REdis Serialization Protocol) header with an excessively large declared length. The flaw occurs because redis-parser fails to validate the multi-bulk length value during RESP protocol parsing. Successful exploitation can lead to a Denial of Service (DoS) by crashing the Node.js client process.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-24 14:05:49 UTC
redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a crafted RESP header with a length above 2^32-1 to crash the Node.js client process.