Skip to main content
HIGH

CVE-2026-93435

CVSS v3

7.5

HIGH

EPSS Score

0.6 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks.

Technical details

Published
2026-09-17
Last Modified
2026-09-17

Frequently asked questions

What is CVE-2026-93435?

redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks.

Is CVE-2026-93435 actively exploited?

Active exploitation of CVE-2026-93435 has not been confirmed. Its EPSS score was 0.6% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-93435?

CVE-2026-93435 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2026-93435 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key