CRITICAL
Apache Kvrocks: Stack buffer overflow in Lua bit.tohex()
Published Jun 25, 2026
10.0
CRITICALCVSS 4.0
EPSS 0.48%
Description
Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0.
Users are recommended to upgrade to version 2.16.0, which fixes the issue.
Affected products
-
- Version 2.0.4StatusaffectedConstraints<=2.15.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Kvrocks | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://www.openwall.com/lists/oss-security/2026/06/25/4
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39332 Advisory
- https://lists.apache.org/thread/11sr3bkkhkk0q01odgw6ddsj7fzo31pt vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/25/4 | ||
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39332 | Advisory | |
| https://lists.apache.org/thread/11sr3bkkhkk0q01odgw6ddsj7fzo31pt | vendor-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jun 25, 2026
Updated Jun 25, 2026
Reserved May 18, 2026
Link CVE-2026-46752
CISA Vulnrichment
Updated Jun 25, 2026
ENISA EUVD
EUVD-2026-39332 Assigner apache
Published Jun 25, 2026
Updated Jun 25, 2026
Exploited since n/a
Link EUVD-2026-39332