The issue only occurs when the CLIENT SETINFO command times out during connection establishment. The following circumstances can cause such a timeout:
DisableIndentity flag.The impact differs by use case:
We prepared a fix in https://github.com/redis/go-redis/pull/3295 and plan to release patch versions soon.
You can prevent the vulnerability by setting the flag DisableIndentity (BTW: We also need to fix the spelling.) to true when constructing the client instance.
Akhass Wasti Ramin Ghorashi Anton Amlinger Syed Rahman Mahesh Venkateswaran Sergey Zavoloka Aditya Adarwal Abdulla Anam Abd-Alhameed Alex Vanlint Gaurav Choudhary Vedanta Jha Yll Kelani Ryan Picard
{
"github_reviewed": true,
"github_reviewed_at": "2025-03-20T18:49:59Z",
"severity": "LOW",
"nvd_published_at": "2025-03-20T18:15:19Z",
"cwe_ids": [
"CWE-20"
]
}