THREAT OPS › Threat News › [GHSA] GHSA-w6f5-v2h6-g786 (critical) — Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections
[GHSA] GHSA-w6f5-v2h6-g786 (critical) — Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections
GHSA-w6f5-v2h6-g786 Severity: critical CVE: CVE-2026-84372
Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections
### Summary
An improper CRLF neutralization flaw in Predis' pipeline handling on aggregate connections lets an unauthenticated attacker who can influence any pipelined argument — a value **or** a key, e.g. a URL slug u
MITRE ATT&CK techniques
- Data DestructionT1485
Indicators of compromise
- CVE-2026-84372cve
- http://127.0.0.1:8080/?seedurl
- http://127.0.0.1:8080/?slug=PAD4%0D%0A*1%0D%0A%247%0D%0AFLUSHDBurl
Original source: https://github.com/advisories/GHSA-w6f5-v2h6-g786