CVE-2021-32675 is an uncontrolled memory-consumption vulnerability in Redis RESP request parsing. Redis allocates memory from client-controlled multi-bulk element counts and bulk element sizes. An attacker can submit specially crafted RESP requests over multiple connections to induce significant server memory allocation. Because the same parser processes authentication requests, exploitation can be performed by unauthenticated clients.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This seven-file Python proof-of-concept repository targets Redis CVE-2021-32675, a network-accessible memory-exhaustion condition associated with processing oversized RESP bulk-string declarations. The main entry point, exploit.py, builds a header-only RESP array request containing a configurable declared bulk length, opens a configurable number of TCP sockets, and retains accepted sockets for a configurable duration. The intended effect is large server-side buffer reservations with only a few bytes sent by the attacker. It provides baseline/post-test/final Redis memory reporting through redis-py, or a raw TCP PING fallback if INFO is unavailable, and reports whether connections appeared accepted or were immediately rejected. The repository also contains Docker Compose lab material: a nominally vulnerable redis:7.0-alpine service exposed on port 6380 with no password, 512 MB proto-max-bulk-len, 1 GB client query buffer, and no maxmemory cap; and a redis:8.0-alpine mitigated service exposed on 6381 with authentication, smaller protocol/query-buffer limits, and a memory cap. requirements.txt pins colorama and redis. The exploit is an operational DoS tool rather than merely a detector because it actively creates and holds resource-consuming connections. A noteworthy implementation limitation is that --password/--auth is passed only to the monitoring Redis client and is never sent as an AUTH command over the malicious raw sockets, so the exploit itself does not support authenticated targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Redis denial-of-service vulnerability triggered through a Redis Serialization Protocol (RESP) request.
Denial-of-service vulnerability in Redis via a Redis Serialization Protocol request.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.