CVE-2025-26413 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index…
High CVSS: 7.5

CVE-2025-26413

Improper Input Validation vulnerability in Apache Kvrocks.

The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index
of a string. So it will cause the server to crash due to its index is  out of range.
This issue affects Apache Kvrocks: through 2.11.1.

Users are recommended to upgrade to version 2.12.0, which fixes the issue.
Vendor
Apache
Product
Kvrocks
CWE
CWE-20
Yayın Tarihi
2025-04-22 08:15:28
Güncelleme
2025-06-23 19:25:25
Source Identifier
security@apache.org
KEV Date Added
-

Kategoriler

Referanslar