GSSA-2026-04-QH1CCPGITLAB-GSSA-2026-04-QH1CCPApril 25, 20266.5 Medium
Cache invalidation used blocking Redis KEYS command in cobc-events
`CacheService.invalidatePattern` called `redis.keys(pattern)`, which blocks the Redis instance. On large keyspaces this could stall the entire Redis server and create a denial-of-service condition.
Affected (1)
- gelhaus-solutionscobc-events
- ≥ 0.0.0Fixed in 1.0.1
Mitigations
Workarounds
- Deploy a dedicated Redis instance for cobc-events so blocking calls cannot affect other services.
- Avoid triggering bulk cache invalidation paths until upgrade.
Solutions
- Upgrade cobc-events to 1.0.1 or later.
Overview
CacheService.invalidatePattern called redis.keys(pattern), which blocks the Redis instance. On large keyspaces this could stall the entire Redis server and create a denial-of-service condition.
Severity
CVSS v3
6.5 Medium
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- None
- Availability
- High
Weaknesses (3)
References (3)
- Patch in src/utils/cache.js (Patch)
- Redis: KEYS command (production warning) (Technical description)
- Redis: SCAN command (Technical description)
Credits (5)
- Enno GelhausFinder · egelhaus@ennogelhaus.de
- Enno GelhausAnalyst · egelhaus@ennogelhaus.de
- Enno GelhausRemediation developer · egelhaus@ennogelhaus.de
- Enno GelhausRemediation reviewer · egelhaus@ennogelhaus.de
- Claude (Anthropic) — automated audit assistantTool · https://claude.com
Context
Impacts
Denial of service via Redis blocking on large keyspaces
CAPEC-130
Timeline
- 04/25/2026 00:00
Internal security audit started
- 04/25/2026 06:00
Vulnerability identified during audit
- 04/25/2026 12:00
Patch developed and merged to main
- 04/25/2026 14:00
cobc-events 1.0.1 released
- 04/25/2026 15:00
Advisory published