CVE-2026-21874: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-21874 is a Redis connection leak vulnerability in NiceGUI, a Python-based UI framework, that allows unauthenticated attackers to exhaust Redis connections by repeatedly opening and closing browser tabs on any NiceGUI application using Redis-backed storage. Affected versions span from v2.10.0 through 3.4.1; version 3.5.0 contains the fix. The vulnerability was disclosed on January 8, 2026, via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).

Technical details

The root cause is classified as CWE-772 (Missing Release of Resource after Effective Lifetime). When a client disconnects, tab_id is cleared in client.py before the delete() method is called, leaving it as None at cleanup time. As a result, the corresponding RedisPersistentDict — which holds a Redis client connection and a pubsub subscription — cannot be located and its close() method is never invoked. Each browser tab creates one such object, and because connections accumulate without being released, Redis eventually reaches its maxclients limit. The fix in commit 6c52eb2 saves the tab_id before clearing it, introduces a storage.close_tab() method, and properly cancels the listener task and closes both the pubsub and Redis client on disconnect (GitHub Advisory, Patch Commit).

Impact

Successful exploitation causes service degradation of the Redis storage layer for all users of the affected NiceGUI application. Once Redis hits its connection limit, new connections are refused, causing tab and user storage data to fail to load or save, and any Redis-dependent functionality to break. The application itself remains technically online and continues accepting connections, but storage operations fail silently with logged errors. There is no confidentiality or integrity impact; the effect is limited to availability of the storage subsystem (GitHub Advisory).

Exploitability

No authentication or user interaction is required to exploit this vulnerability, and the attack can be performed entirely over the network with low complexity. A proof-of-concept attack script using Playwright to automate repeated browser tab opens/closes is publicly documented in the security advisory itself. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.035% (very low), and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Identify target: Locate a publicly accessible NiceGUI application (versions 2.10.0–3.4.1) that uses Redis-backed storage (i.e., configured with a NICEGUI_REDIS_URL and storage_secret).
  2. Automate tab cycling: Use a browser automation tool such as Playwright to repeatedly open a new browser context, navigate to the target application URL, wait briefly for the page to load (triggering tab storage initialization and Redis connection creation), then close the context — without allowing the connection cleanup to complete.
  3. Repeat at scale: Run the attack loop for a sufficient number of iterations (e.g., 50–100 tabs depending on Redis maxclients setting) to exhaust the Redis connection pool. Each tab creates a RedisPersistentDict with a persistent Redis client and pubsub subscription that is never closed.
  4. Observe degradation: Once Redis reaches its maxclients limit, new storage operations fail with redis.exceptions.ConnectionError: max number of clients reached. Legitimate users lose access to persistent storage (tab/user data not saved), and Redis-dependent features break for all users (GitHub Advisory).

Indicators of compromise

  • Logs: NiceGUI application logs showing repeated Could not load data from Redis warnings; redis.exceptions.ConnectionError: max number of clients reached errors in application logs; delete: tab_id=None error log entries indicating failed cleanup.
  • Redis Metrics: Rapidly increasing connected_clients count in Redis INFO clients output without a corresponding decrease; connected_clients approaching or reaching the configured maxclients value.
  • Network: High volume of short-lived HTTP/WebSocket connections to the NiceGUI application from one or more source IPs, consistent with automated browser tab cycling.
  • Process/Application Behavior: Storage operations failing for legitimate users; NiceGUI logging warnings about broken storage functionality while the application itself remains running (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade NiceGUI to version 3.5.0 or later, which properly closes Redis connections and pubsub subscriptions when a client tab disconnects (NiceGUI v3.5.0, Patch Commit). For deployments that cannot be immediately patched, consider implementing network-level rate limiting or access controls to restrict the rate at which clients can open and close connections. Additionally, monitor Redis connection counts and configure alerting when connected_clients approaches maxclients, and consider temporarily increasing the Redis maxclients limit as a short-term buffer while planning the upgrade.

Community reactions

The vulnerability was published by maintainer falkoschindler via GitHub Security Advisory on January 8, 2026, crediting researcher yudelevi for discovery and evnchn for remediation analysis. The fix was included in the NiceGUI v3.5.0 release alongside several other security patches. No significant broader media coverage or notable external researcher commentary has been identified beyond the official advisory (GitHub Advisory, NiceGUI v3.5.0).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management