Resource Exhaustion Vulnerability in Redis Product by Redis Labs
CVE-2026-93572

Currently unrated

What is CVE-2026-93572?

The Redis product contains a vulnerability in the RedisArrayAggregator component where improper handling of nested RESP array headers may lead to a resource exhaustion attack. By sending manipulated nested array headers, an attacker can trigger the allocation of excessive memory resources, potentially impacting server performance. Despite the introduction of maxElements and maxNestedArrayDepth limits, the eager allocation behavior results in significant backing memory consumption. This can allow an attacker to reserve millions of child slots, exhausting available system resources, and potentially causing service disruptions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.