VYPR
Unrated severityNVD Advisory· Published Nov 28, 2025· Updated Nov 28, 2025

Apache Kvrocks: MONITOR command reveals plaintext credentials to non-admins

CVE-2025-59792

Description

Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks.

This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0.

Users are recommended to upgrade to version 2.14.0, which fixes the issue.

Affected products

2
  • Apache/Kvrocksllm-create
    Range: >=1.0.0 <=2.13.0
  • Apache Software Foundation/Apache Kvrocksv5
    Range: 1.0.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.