cbcvebase.

Apache Software Foundation Apache Kvrocks vulnerabilities

9 known vulnerabilities affecting apache_software_foundation/apache_kvrocks.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM4LOW1

Vulnerabilities

Page 1 of 1
CVE-2026-46752P2CRITICALCVSS 10.0≥ 2.0.4, ≤ 2.15.02026-06-25
CVE-2026-46752 [CRITICAL] CWE-122 CVE-2026-46752: Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
nvd
CVE-2026-41566P3CRITICALCVSS 9.4≥ 2.8.0, ≤ 2.15.02026-06-25
CVE-2026-41566 [CRITICAL] CWE-280 CVE-2026-41566: Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This i Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
nvd
CVE-2025-26413P3HIGHCVSS 7.5≤ 2.11.12025-04-22
CVE-2025-26413 [HIGH] CWE-20 CVE-2025-26413: Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is out of range. This issue affects Apache Kvrocks: through 2.11.1. Users are recommended to upgrade to version 2.12.0, which
nvd
CVE-2016-10517P3HIGHCVSS 7.4≤ 2.11.02017-10-24
CVE-2016-10517 [HIGH] CWE-254 CVE-2016-10517: networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for PO networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).
nvd
CVE-2026-54226P3MEDIUMCVSS 6.4≥ 2.6.0, ≤ 2.15.02026-06-25
CVE-2026-54226 [MEDIUM] CWE-190 CVE-2026-54226: A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. U A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
nvd
CVE-2026-46751P4MEDIUMCVSS 5.5≥ 2.2.0, ≤ 2.15.02026-06-25
CVE-2026-46751 [MEDIUM] CVE-2026-46751: A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0. U A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
nvd
CVE-2025-59790P4MEDIUMCVSS 5.4≥ 2.9.0, ≤ 2.13.02025-11-28
CVE-2025-59790 [MEDIUM] CWE-269 CVE-2025-59790: Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: f Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.
nvd
CVE-2025-59792P4MEDIUMCVSS 5.3≥ 1.0.0, ≤ 2.13.02025-11-28
CVE-2025-59792 [MEDIUM] CWE-312 CVE-2025-59792: Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue af Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.
nvd
CVE-2026-45188P4LOWCVSS 2.4≥ 1.0.0, ≤ 2.15.02026-06-25
CVE-2026-45188 [LOW] CWE-23 CVE-2026-45188: Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1. Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
nvd
Apache Software Foundation Apache Kvrocks vulnerabilities | cvebase