Intel

AIKIDO-2026-10169

taskiq-redis is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

24

Low Risk

This Affects:

PYTHONtaskiq-redis
1.0.9 - 1.2.1
Fixed in 1.2.2

TL;DR

Affected versions of this package are vulnerable to denial of service due to an infinite lock in the Redis stream broker. If a worker crashes or is terminated while holding the autoclaim lock, the lock is never released, preventing further message processing and causing the queue to stall.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

taskiq-redis is vulnerable to Denial of Service (DoS) in versions 1.0.9 - 1.2.1.

How to fix this

Upgrade the taskiq-redis library to the patch version.

Background Info