Kvrocks Apache Kvrocks

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Apache Kvrocks.

By the Year

In 2026 there have been 0 vulnerabilities in Apache Kvrocks. Last year, in 2025 Kvrocks had 4 security vulnerabilities published. Right now, Kvrocks is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 4 5.35

It may take a day or so for new Kvrocks vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apache Kvrocks Security Vulnerabilities

Apache Kvrocks 1.0.02.13.0 MONITOR plaintext creds leak (CVE202559792)
CVE-2025-59792 5.3 - Medium - November 28, 2025

Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.

Cleartext Storage of Sensitive Information

Apache Kvrocks 2.9.02.13.0 Improper Privilege Management (Fixed 2.14.0)
CVE-2025-59790 5.4 - Medium - November 28, 2025

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.

Improper Privilege Management

Apache Kvrocks 2.11.1 Improper SETRANGE Integer Validation Crash
CVE-2025-26413 - April 22, 2025

Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is  out of range. This issue affects Apache Kvrocks: through 2.11.1. Users are recommended to upgrade to version 2.12.0, which fixes the issue.

Cross-Protocol Scripting CVE-2025-25069 in Apache Kvrocks <2.11.1
CVE-2025-25069 - February 07, 2025

A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, which can be dangerous when it is chained with SSRF. It is similiar to CVE-2016-10517 in Redis. This issue affects Apache Kvrocks: from the initial version to the latest version 2.11.0. Users are recommended to upgrade to version 2.11.1, which fixes the issue.

Misinterpretation of Input

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apache Kvrocks or by Apache? Click the Watch button to subscribe.

Apache
Vendor

subscribe