{
  "from_raw": "Hulk Lin <hulk@apache.org>",
  "from": "Hulk Lin <hu...@apache.org>",
  "gravatar": "efe72ee5aa392a27eec93825ccfb3768",
  "to": "an...@apache.org,\n de...@kvrocks.apache.org",
  "subject": "CVE-2026-46751: Apache Kvrocks: Does not remove the unsafe loadstring function from its Lua sandbox, allowing a user who can run EVAL scripts to load crafted, unvalidated bytecode that crashes the server process, resulting in a remote denial of service.",
  "message-id": "<484d7484-3461-8c44-ac87-d79b162b7711@apache.org>",
  "mid": "rwrb0sz8bdg665cx6jmgxzozwq8bppom",
  "permalinks": [
    "rwrb0sz8bdg665cx6jmgxzozwq8bppom",
    "rfd5c6ea68f56dfc0f623f15a458cfba82a9feb7bc7a117d7c42e6ec3@<announce.apache.org>"
  ],
  "dbid": "6e22dc2e50812c8592f046d4e19764fd7cef905d2c7bfd66cace9f05e2ca51fe",
  "cc": "de...@kvrocks.apache.org",
  "epoch": 1782354068,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/06/25 02:21:08",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: \n\nAffected versions:\n\n- Apache Kvrocks (apache/kvrocks) 2.2.0 through 2.15.0\n\nDescription:\n\nA vulnerability in Apache Kvrocks.\n\nThis issue affects Apache Kvrocks: from 2.2.0 through 2.15.0.\n\nUsers are recommended to upgrade to version 2.16.0, which fixes the issue.\n\nCredit:\n\n4ra2n (A code security AI agent) (finder)\n\nReferences:\n\nhttps://kvrocks.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-46751\n\n",
  "body_short": "Severity: \n\nAffected versions:\n\n- Apache Kvrocks (apache/kvrocks) 2.2.0 through 2.15.0\n\nDescription:\n\nA vulnerability in Apache Kvrocks.\n\nThis issue affects Apache Kvrocks: from 2.2.0 through 2.15.0.\n\n",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2510,
  "id": "rwrb0sz8bdg665cx6jmgxzozwq8bppom"
}