CVE-2025-25069
A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, which can be dangerous when it is chained with SSRF. It is similiar to CVE-2016-10517 in Redis. This issue affects Apache Kvrocks: from the initial version to the latest version 2.11.0. Users are recommended to upgrade to version 2.11.1, which fixes the issue.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.81%
- CWE
- CWE-115
- Published
- 2025-02-07
- Last modified
- 2026-03-12
Affected products
- Apache Software Foundation Apache Kvrocks
Weakness type
Related vulnerabilities
- CVE-2026-63650 — OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be...
- CVE-2026-17566 — pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
- CVE-2026-17351 — pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
- CVE-2026-12491 — Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectations
- CVE-2025-68113 — ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
- CVE-2025-55303 — Unauthorized third-party images in Astro’s _image endpoint
- CVE-2025-54584 — GitProxy is vulnerable to a packfile parsing exploit
- CVE-2025-5826 — Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability