{
  "from_raw": "Hulk Lin <hulk@apache.org>",
  "from": "Hulk Lin <hu...@apache.org>",
  "gravatar": "efe72ee5aa392a27eec93825ccfb3768",
  "to": "an...@apache.org,\n de...@kvrocks.apache.org",
  "subject": "CVE-2026-46752: Apache Kvrocks: Stack buffer overflow in Lua bit.tohex()",
  "message-id": "<71d06fd2-7b61-4e8e-ae56-a08fb4746b43@apache.org>",
  "mid": "9hqdrfn8h0bxpd7hg8mv4l78440y9xd4",
  "permalinks": [
    "9hqdrfn8h0bxpd7hg8mv4l78440y9xd4",
    "r3c79efde12857813e683e086012e784ae006d72746f6d8ccde323ecc@<announce.apache.org>"
  ],
  "dbid": "8645340dd6d8bac87d0902981e2bfae1d5d3a82a8df14341d010812c0fa1e291",
  "cc": "de...@kvrocks.apache.org",
  "epoch": 1782354146,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/06/25 02:22:26",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: \n\nAffected versions:\n\n- Apache Kvrocks (apache/kvrocks) 2.0.4 through 2.15.0\n\nDescription:\n\nRedis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks.\n\nThis issue affects Apache Kvrocks: from 2.0.4 through 2.15.0.\n\nUsers are recommended to upgrade to version 2.16.0, which fixes the issue.\n\nCredit:\n\nJincheng Yang (reporter)\n\nReferences:\n\nhttps://kvrocks.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-46752\n\n",
  "body_short": "Severity: \n\nAffected versions:\n\n- Apache Kvrocks (apache/kvrocks) 2.0.4 through 2.15.0\n\nDescription:\n\nRedis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks.\n\nThis issue affects Apach",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2349,
  "id": "9hqdrfn8h0bxpd7hg8mv4l78440y9xd4"
}