THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w6f5-v2h6-g786 (critical) — Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections

[GHSA] GHSA-w6f5-v2h6-g786 (critical) — Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections

highgithub_advisoriesPublished 2026-09-08

GHSA-w6f5-v2h6-g786 Severity: critical CVE: CVE-2026-84372

Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections

### Summary

An improper CRLF neutralization flaw in Predis' pipeline handling on aggregate connections lets an unauthenticated attacker who can influence any pipelined argument — a value **or** a key, e.g. a URL slug u

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w6f5-v2h6-g786