qbm-redis is a module of the qb actor framework. Vulnerability reporting and disclosure follow the framework's process — see the qb SECURITY policy. Do not report security issues through public GitHub issues, pull requests, or discussions.
Security fixes target the module version that ships with the supported qb framework release, which is
the latest minor of the current major — the 3.0.x line. The module is versioned in lockstep with the
framework and is not standalone-configurable, so there is no separate module support window and no
backport to a module version built against an unsupported framework. See the framework policy for details.
qbm-redis parses untrusted bytes from a Redis server connection. When reporting, identify the affected component:
- RESP reply decoding (the parser, type transforms, the
SCANcursor). - Length and bounds handling in the read buffer (
ViewBuffer). - The pub/sub message dispatch path and the command/reply correlation FIFO.
- The auto-reconnect connect path and connection lifecycle.
The module fails closed on hostile input: handler exceptions are contained at the noexcept onMessage
boundary, a throwing pub/sub callback cannot desynchronize the reply FIFO, ViewBuffer length bounds are
overflow-safe, a corrupt RESP terminator faults the connection, and numeric parsing rejects trailing
garbage. Report any case where these protections can be bypassed, or where a malicious server response
reaches an unsafe path.
Connect only to a trusted Redis server over a trusted network or TLS, and treat the server as part of your trust boundary.