CVE-2025-25069

A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, which can be dangerous when it is chained with SSRF. It is similiar to CVE-2016-10517 in Redis. This issue affects Apache Kvrocks: from the initial version to the latest version 2.11.0. Users are recommended to upgrade to version 2.11.1, which fixes the issue.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:kvrocks:*:*:*:*:*:*:*:*

History

16 Jul 2025, 14:47

Type Values Removed Values Added
First Time Apache
Apache kvrocks
CPE cpe:2.3:a:apache:kvrocks:*:*:*:*:*:*:*:*
References () https://www.cve.org/CVERecord?id=CVE-2016-10517 - () https://www.cve.org/CVERecord?id=CVE-2016-10517 - Not Applicable
References () https://lists.apache.org/thread/gbxv9gpsskmdzg6z48zm3tvo8cyo9v3t - () https://lists.apache.org/thread/gbxv9gpsskmdzg6z48zm3tvo8cyo9v3t - Mailing List, Vendor Advisory

13 Feb 2025, 22:15

Type Values Removed Values Added
CWE CWE-115

07 Feb 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-07 13:15

Updated : 2025-07-16 14:47


NVD link : CVE-2025-25069

Mitre link : CVE-2025-25069


JSON object : View

Products Affected

apache

  • kvrocks
CWE

No CWE.