CVE-2025-26413
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 22, 2025
Updated: May 12, 2025
CWE ID 20
Summary
CVE-2025-26413 is an Input Validation vulnerability affecting Apache Kvrocks. The SETRANGE command fails to verify if the 'offset' argument is a positive integer, leading to out-of-range indexing and server crashes. This issue impacts Apache Kvrocks versions up to 2.11.1. To mitigate this risk, it is highly recommended that users upgrade to the latest version, 2.12.0, which includes the necessary patch to resolve the vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.