CVE-2025-25069
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-25069 is a Cross-Protocol Scripting vulnerability affecting Apache Kvrocks. This issue allows a maliciously crafted request to be treated as a valid RESP response, triggering dangerous database operations. Kvrocks fails to detect "Host:" or "POST" in RESP requests, making it possible for attackers to exploit this vulnerability and chain it with Server Side Request Forgery (SSRF). This issue is reminiscent of CVE-2016-10517 in Redis. Affecting all versions of Apache Kvrocks, from the initial release to 2.11.0, users are strongly advised to upgrade to version 2.11.1 to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.