Apache kvrocks
This hub aggregates every CVE we track for Apache kvrocks, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
9
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM3HIGH1
Monthly trend
0
0
0
0
1
0
1
0
0
0
0
0
0
2
0
0
0
0
0
0
5
0
0
0
2024-102026-09
Latest CVEs
The 9 most recently published vulnerabilities affecting Apache kvrocks.
- CVE-2026-41566Apache Kvrocks: Improper permission for the APPLYBATCH command
- CVE-2026-45188Apache Kvrocks: Replication Fullsync Path Traversal via Unvalidated Filename Handling
- CVE-2026-46751Apache Kvrocks: Does not remove the unsafe loadstring function from its Lua sandbox, allowing a user who can run EVAL scripts to load crafted, unvalidated bytecode that crashes the server process, resulting in a remote denial of service.
- CVE-2026-46752Apache Kvrocks: Stack buffer overflow in Lua bit.tohex()
- CVE-2026-54226Apache Kvrocks: RESTORE IntSet Integer Overflow Leads to Remote DoS
- CVE-2025-59792Apache Kvrocks: MONITOR command reveals plaintext credentials to non-admins5.3
- CVE-2025-59790Apache Kvrocks: RESET command grants admin privileges5.4
- CVE-2025-26413Apache Kvrocks: The server was crashed by the negative offset7.5
- CVE-2025-25069Apache Kvrocks: Cross-Protocol Scripting Vulnerability6.5
Product normalization is registry-driven with AI assist and human review. How it works