Unrated severityNVD Advisory· Published Jun 25, 2026· Updated Jun 25, 2026
Apache Kvrocks: Does not remove the unsafe loadstring function from its Lua sandbox, allowing a user who can run EVAL scripts to load crafted, unvalidated bytecode that crashes the server process, resulting in a remote denial of service.
CVE-2026-46751
Description
A vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0.
Users are recommended to upgrade to version 2.16.0, which fixes the issue.
Patches
Vulnerability mechanics
References
1- lists.apache.org/thread/cjjk4gq1nkb7pooqc37gz0blvdkqgv5zmitrevendor-advisory
News mentions
0No linked articles in our index yet.