CVE-2025-26413

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 22, 2025
Updated: May 12, 2025
CWE ID 20

Summary

CVE-2025-26413 is an Input Validation vulnerability affecting Apache Kvrocks. The SETRANGE command fails to verify if the 'offset' argument is a positive integer, leading to out-of-range indexing and server crashes. This issue impacts Apache Kvrocks versions up to 2.11.1. To mitigate this risk, it is highly recommended that users upgrade to the latest version, 2.12.0, which includes the necessary patch to resolve the vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share