CVE-2025-26413

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
22/04/2025
Last modified:
23/06/2025

Description

Improper Input Validation vulnerability in Apache Kvrocks.<br /> <br /> The SETRANGE command didn&amp;#39;t check if the `offset` input is a positive integer and use it as an index<br /> of a string. So it will cause the server to crash due to its index is  out of range.<br /> This issue affects Apache Kvrocks: through 2.11.1.<br /> <br /> Users are recommended to upgrade to version 2.12.0, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:kvrocks:*:*:*:*:*:*:*:* 2.12.0 (excluding)