Apache Kvrocks was reported as affected by two Redis Lua flaws, CVE-2024-31449 and CVE-2025-49844, with project-linked fixes already in place despite the absence of a formal security advisory. In the oss-sec discussion, restored Apache Kvrocks GitHub issues identified CVE-2024-31449 as a stack buffer overflow in Lua bit.tohex() and CVE-2025-49844 as a use-after-free in the Lua parser function luaY_parser, while a maintainer pull request was said to reference both vulnerabilities directly.
The disclosure became muddled after the related GitHub issues were temporarily renamed as duplicates and marked to be ignored, prompting questions on oss-sec about whether the references were valid and whether any official notice existed. Jincheng Yang said the issue titles and descriptions were restored after the rename caused confusion and said the change was not intended to conceal the bugs; he also said ASF Security planned to coordinate with the Kvrocks team to publish Kvrocks-specific CVE IDs, leaving the project in a state where fixes appear to exist but formal advisory tracking remains incomplete.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-16, Alan Coopersmith replied on oss-sec that the referenced Kvrocks issues appeared to be marked 'Duplicate - please ignore' and submitted in error, casting doubt on the public tracking and advisory status of the alleged fixes.
Yang said ASF Security planned to coordinate with the Kvrocks team to publish Kvrocks-specific CVE IDs for the vulnerabilities affecting the project.
In the oss-sec discussion, Yang stated that the impacts had been reported to the Kvrocks project, acknowledged by maintainers, and fixed already, though no formal advisory had yet been published.
Later on 2026-04-11, Jincheng Yang said he restored the original titles and content of the Kvrocks GitHub issues, identifying CVE-2024-31449 and CVE-2025-49844 and noting that a maintainer fix pull request explicitly referenced both CVEs.
On 2026-04-11, Apache Kvrocks GitHub issues #3433 and #3434 were renamed and edited to say they were submitted in error and marked as duplicates, obscuring their prior references to Redis Lua vulnerabilities.
On GitHub, Apache Kvrocks issue #3434 was opened to report that Kvrocks was affected by CVE-2025-49844, a use-after-free in the Lua parser inherited from the RocksLabs/lua code path originating from Redis. The report said the flaw could enable authenticated remote code execution when Kvrocks is built with PUC Lua (-DENABLE_LUAJIT=OFF), noted default LuaJIT builds were not affected, and described the fix approach.
On GitHub, Apache Kvrocks issue #3433 was opened to report that Kvrocks was affected by CVE-2024-31449, a stack buffer overflow in the Redis-derived RocksLabs/lua bit.tohex() implementation. The report included a redis-cli proof of concept against Kvrocks, identified the vulnerable code path, and proposed remediation based on the upstream Redis fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.