Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-84372

Опубликовано: 01 сент. 2026
Источник: debian
EPSS Низкий

Описание

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode("\r\n") instead of honoring RESP length prefixes. Attacker-controlled keys or values containing CRLF sequences can therefore be interpreted by Command::deserializeCommand() as additional commands. On cluster connections, ClusterStrategy::getFakeKey() can route injected keyless commands using the literal fake key value "key", permitting operations such as shard-wide cache deletion, targeted data modification, data reads, or node disruption. On replication connections, malformed reparsing can throw an uncaught exception and repeatedly terminate affected requests. Only pipeline() reaches this vulnerable path; transaction() and MULTI are not affected. This issue is fixed in version 3.3.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php-nrk-predisnot-affectedpackage

Примечания

  • https://github.com/predis/predis/security/advisories/GHSA-w6f5-v2h6-g786

  • https://github.com/predis/predis/issues/1574

  • https://github.com/predis/predis/pull/1586

  • Fixed by: https://github.com/predis/predis/commit/053cb4b6ac7fb1f469ead96a78d059bc0458e408 (v3.3.0)

EPSS

Процентиль: 35%
0.00415
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
16 дней назад

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode("\r\n") instead of honoring RESP length prefixes. Attacker-controlled keys or values containing CRLF sequences can therefore be interpreted by Command::deserializeCommand() as additional commands. On cluster connections, ClusterStrategy::getFakeKey() can route injected keyless commands using the literal fake key value "key", permitting operations such as shard-wide cache deletion, targeted data modification, data reads, or node disruption. On replication connections, malformed reparsing can throw an uncaught exception and repeatedly terminate affected requests. Only pipeline() reaches this vulnerable path; transaction() and MULTI are not affected. This issue is fixed in version 3.3.0.

CVSS3: 9.8
nvd
16 дней назад

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode("\r\n") instead of honoring RESP length prefixes. Attacker-controlled keys or values containing CRLF sequences can therefore be interpreted by Command::deserializeCommand() as additional commands. On cluster connections, ClusterStrategy::getFakeKey() can route injected keyless commands using the literal fake key value "key", permitting operations such as shard-wide cache deletion, targeted data modification, data reads, or node disruption. On replication connections, malformed reparsing can throw an uncaught exception and repeatedly terminate affected requests. Only pipeline() reaches this vulnerable path; transaction() and MULTI are not affected. This issue is fixed in version 3.3.0.

CVSS3: 9.8
github
9 дней назад

Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections

CVSS3: 9.8
fstec
около 1 года назад

Уязвимость метода AbstractAggregateConnection::write() PHP-клиента для баз данных Redis и Valkey Predis, позволяющая нарушителю выполнить произвольные команды и вызвать отказ в обслуживании

EPSS

Процентиль: 35%
0.00415
Низкий