#VU119155 Input validation error in Apache Kvrocks - CVE-2025-26413
Published: December 4, 2025
Apache Kvrocks
Apache Foundation
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to the SETRANGE command does not check if the "offset" input is a positive integer and use it as an index of a string. A remote user can send a specially crafted request to the application and perform a denial of service attack.