Hi Alan, Good catch -- sorry for the confusion. The "Duplicate - please ignore" titles on #3433 and #3434 are my own housekeeping rename, done on 2026-04-11, AFTER the Kvrocks maintainers had already closed both issues on 2026-04-09 via a single fix PR. The original bodies were the actual vulnerability reports.
The authoritative, non-renamed evidence on the Kvrocks side is: https://github.com/apache/kvrocks/pull/3435 Title: "fix(script): upgrade Lua version to fix CVE-2024-31449 and CVE-2025-49844" Author: jihuayu (Kvrocks committer) Merged: 2026-04-09 03:57 UTC Auto-closed #3433 and #3434. So the Kvrocks project itself, in its own fix PR title, names both CVEs as applicable to apache/kvrocks. The downstream impact is not in doubt -- what remains pending is a formal ASF advisory / GHSA / Kvrocks-specific CVE ID, which was the original subject of my post. Off-list update: ASF Security has since confirmed they plan to coordinate with Kvrocks to publish CVEs for these issues. Best, Jincheng Yang Xidian University
