Apache
Apache Kvrocks: vulnerabilities and CVEs
Apache Kvrocks has 9 published vulnerabilities, 7 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs9
Last 12 months7
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54226 | Medium (6.4) | 0.40% | — | Jun 25, 2026 | A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. |
| CVE-2026-46752 | Critical (10) | 0.48% | — | Jun 25, 2026 | Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. |
| CVE-2026-46751 | Medium (5.5) | 0.33% | — | Jun 25, 2026 | A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. |
| CVE-2026-45188 | Low (2.4) | 0.15% | — | Jun 25, 2026 | Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. |
| CVE-2026-41566 | Critical (9.4) | 0.36% | — | Jun 25, 2026 | Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. |
| CVE-2025-59792 | Medium (5.3) | 0.30% | — | Nov 28, 2025 | Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the… |
| CVE-2025-59790 | Medium (5.4) | 0.41% | — | Nov 28, 2025 | Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue. |
| CVE-2025-26413 | High (7.5) | 0.75% | — | Apr 22, 2025 | Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to… |
| CVE-2025-25069 | Medium (6.5) | 0.81% | — | Feb 7, 2025 | A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.