CVE-2026-84372 with a maximum severity CVSS score of 9.8, has been discovered in the Predis client. This flaw allows an attacker to inject malicious commands via CRLF smuggling in pipelined commands on aggregate connections, enabling them to wipe entire cache clusters, steal encryption keys, poison cached session data, or trigger a repeatable denial of service state. The vulnerability stems from an improper re-parsing of serialized pipeline buffers by the Predis client, which honors exact byte length prefixes instead of splitting data streams using carriage return line feed characters. An external attacker can embed these sequences inside a standard URL slug cache key, causing the client to misinterpret them as hard command boundaries. This issue directly impacts versions 3.0.0-RC1 through 3.2.0 and has significant business impact due to the high popularity of Predis, with over 8.1 million downloads every month. The proof-of-concept exploit code is publicly available, increasing the risk of active exploitation.
We recommend you to update predis to version 3.6.0.[/subscribe_to_unlock_form]
CVE-2026-84372 with a maximum severity CVSS score of 9.8, has been discovered in the Predis client. This flaw allows an attacker to inject malicious commands via CRLF smuggling in pipelined commands on aggregate connections, enabling them to wipe entire cache clusters, steal encryption keys, poison cached session data, or trigger a repeatable denial of service state. The vulnerability stems from an improper re-parsing of serialized pipeline buffers by the Predis client, which honors exact byte length prefixes instead of splitting data streams using carriage return line feed characters. An external attacker can embed these sequences inside a standard URL slug cache key, causing the client to misinterpret them as hard command boundaries. This issue directly impacts versions 3.0.0-RC1 through 3.2.0 and has significant business impact due to the high popularity of Predis, with over 8.1 million downloads every month. The proof-of-concept exploit code is publicly available, increasing the risk of active exploitation.
We recommend you to update predis to version 3.6.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]