taskiq-redis is vulnerable to Denial of Service (DoS)
24
Low Risk
Affected versions of this package are vulnerable to denial of service due to an infinite lock in the Redis stream broker. If a worker crashes or is terminated while holding the autoclaim lock, the lock is never released, preventing further message processing and causing the queue to stall.
You are affected if you are using a version that falls within the vulnerable range.
taskiq-redis is vulnerable to Denial of Service (DoS) in versions 1.0.9 - 1.2.1.
Upgrade the taskiq-redis library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant