PT-2026-2113 · Redis+1 · Redis+1
Yudelevi
·
Published
2026-01-08
·
Updated
2026-01-08
·
CVE-2026-21874
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
NiceGUI versions 2.10.0 through 3.4.1
Description
NiceGUI is a Python-based UI framework. An unauthenticated attacker can exhaust Redis connections by repeatedly opening and closing browser tabs on any NiceGUI application using Redis-backed storage. Connections are not released, leading to service degradation when Redis reaches its connection limit. NiceGUI continues accepting new connections, but errors are logged and storage functionality is broken.
Recommendations
Upgrade to version 3.5.0 or later.
Exploit
Fix
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nicegui
Redis