GHSA-92cp-5422-2mw7
Dashboard / Vulnerabilities / GHSA-92cp-5422-2mw7
GHSA-92cp-5422-2mw7
Summary: go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment
Details: ### Impact The issue only occurs when the `CLIENT SETINFO` command times out during connection establishment. The following circumstances can cause such a timeout: 1. The client is configured to transmit its identity. This can be disabled via the `DisableIndentity` flag. 2. There are network connectivity issues 3. The client was configured with aggressive timeouts The impact differs by use case: * **Sticky connections**: Rather than using a connection from the pool on-demand, the caller can stick with a connection. Then you receive persistent out-of-order responses for the lifetime of the connection. * **Pipelines**: All commands in the pipeline receive incorrect responses. * **Default connection pool usage without pipelining**: When used with the default [ConnPool](https://github.com/redis/go-redis/blob/8fadbef84a3f4e7573f8b38e5023fd469470a8a4/internal/pool/pool.go#L77) once a connection is returned after use with [ConnPool#Put](https://github.com/redis/go-redis/blob/8fadbef84a3f4e7573f8b38e5023fd469470a8a4/internal/pool/pool.go#L366) the read buffer will be checked and the connection will be marked as bad due to the unread data. This means that at most one out-of-order response before the connection is discarded. ### Patches We prepared a fix in https://github.com/redis/go-redis/pull/3295 and plan to release patch versions soon. Versions 9.7.2, 9.6.3, and 9.5.5 were patched. However, 9.7.2 has been yanked, making 9.7.3 the lowest available 9.7.x version with a patch. ### Workarounds You can prevent the vulnerability by setting the flag `DisableIndentity` (BTW: We also need to fix the spelling.) to `true` when constructing the client instance. ### Credit Akhass Wasti Ramin Ghorashi Anton Amlinger Syed Rahman Mahesh Venkateswaran Sergey Zavoloka Aditya Adarwal Abdulla Anam Abd-Alhameed Alex Vanlint Gaurav Choudhary Vedanta Jha Yll Kelani Ryan Picard
References: https://github.com/redis/go-redis/security/advisories/GHSA-92cp-5422-2mw7, https://nvd.nist.gov/vuln/detail/CVE-2025-29923, https://github.com/redis/go-redis/pull/3295, https://github.com/redis/go-redis/commit/d236865b0cfa1b752ea4b7da666b1fdcd0acebb6, https://github.com/redis/go-redis
Affected packages
Package
Name: github.com/redis/go-redis/v9
Purl: pkg:golang/github.com/redis/go-redis/v9
Affected ranges
Type: SEMVER
Events:
