GHSA-3gvw-xg56-j2xmMediumCVSS 7.1

In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding and...

Published
September 17, 2026
Last Modified
September 22, 2026

🔗 CVE IDs covered (1)

📋 Description

In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding and total length but never checked that string-carrying extensions are properly null-terminated, allowing a crafted packet to trigger out-of-bounds reads when the payload is later consumed as a C string. This vulnerability can potentially lead to loss of confidentiality or remote denial of service. Redis Software / Redis Enterprise are not affected by this issue.

🔗 References (10)