
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21874 is a Redis connection leak vulnerability in NiceGUI, a Python-based UI framework, that allows unauthenticated attackers to exhaust Redis connections by repeatedly opening and closing browser tabs on any NiceGUI application using Redis-backed storage. Affected versions span from v2.10.0 through 3.4.1; version 3.5.0 contains the fix. The vulnerability was disclosed on January 8, 2026, via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).
The root cause is classified as CWE-772 (Missing Release of Resource after Effective Lifetime). When a client disconnects, tab_id is cleared in client.py before the delete() method is called, leaving it as None at cleanup time. As a result, the corresponding RedisPersistentDict — which holds a Redis client connection and a pubsub subscription — cannot be located and its close() method is never invoked. Each browser tab creates one such object, and because connections accumulate without being released, Redis eventually reaches its maxclients limit. The fix in commit 6c52eb2 saves the tab_id before clearing it, introduces a storage.close_tab() method, and properly cancels the listener task and closes both the pubsub and Redis client on disconnect (GitHub Advisory, Patch Commit).
Successful exploitation causes service degradation of the Redis storage layer for all users of the affected NiceGUI application. Once Redis hits its connection limit, new connections are refused, causing tab and user storage data to fail to load or save, and any Redis-dependent functionality to break. The application itself remains technically online and continues accepting connections, but storage operations fail silently with logged errors. There is no confidentiality or integrity impact; the effect is limited to availability of the storage subsystem (GitHub Advisory).
No authentication or user interaction is required to exploit this vulnerability, and the attack can be performed entirely over the network with low complexity. A proof-of-concept attack script using Playwright to automate repeated browser tab opens/closes is publicly documented in the security advisory itself. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.035% (very low), and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
NICEGUI_REDIS_URL and storage_secret).maxclients setting) to exhaust the Redis connection pool. Each tab creates a RedisPersistentDict with a persistent Redis client and pubsub subscription that is never closed.maxclients limit, new storage operations fail with redis.exceptions.ConnectionError: max number of clients reached. Legitimate users lose access to persistent storage (tab/user data not saved), and Redis-dependent features break for all users (GitHub Advisory).Could not load data from Redis warnings; redis.exceptions.ConnectionError: max number of clients reached errors in application logs; delete: tab_id=None error log entries indicating failed cleanup.connected_clients count in Redis INFO clients output without a corresponding decrease; connected_clients approaching or reaching the configured maxclients value.The primary remediation is to upgrade NiceGUI to version 3.5.0 or later, which properly closes Redis connections and pubsub subscriptions when a client tab disconnects (NiceGUI v3.5.0, Patch Commit). For deployments that cannot be immediately patched, consider implementing network-level rate limiting or access controls to restrict the rate at which clients can open and close connections. Additionally, monitor Redis connection counts and configure alerting when connected_clients approaches maxclients, and consider temporarily increasing the Redis maxclients limit as a short-term buffer while planning the upgrade.
The vulnerability was published by maintainer falkoschindler via GitHub Security Advisory on January 8, 2026, crediting researcher yudelevi for discovery and evnchn for remediation analysis. The fix was included in the NiceGUI v3.5.0 release alongside several other security patches. No significant broader media coverage or notable external researcher commentary has been identified beyond the official advisory (GitHub Advisory, NiceGUI v3.5.0).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."