#VU56912 Resource exhaustion in node-redis - CVE-2021-29469
Published: September 29, 2021
node-redis
redis.js
Description
The vulnerability allows a remote attacker to perform a regular expression denial of service (ReDoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources, when a client is in monitoring mode. A remote attacker can trigger resource exhaustion and perform a regular expression denial of service (ReDoS) attack.