Hi Alexander, Thank you -- that was the right call. I have restored both issues to their original titles and content:
https://github.com/apache/kvrocks/issues/3433 [Security] CVE-2024-31449: Stack buffer overflow in Lua bit.tohex() https://github.com/apache/kvrocks/issues/3434 [Security] CVE-2025-49844: Use-after-free in Lua parser (luaY_parser) For the record, the maintainer's fix PR also names both CVEs: https://github.com/apache/kvrocks/pull/3435 The 2026-04-11 rename was a poor judgment call on my part (I thought I was tidying up resolved reports already linked from the fix PR), not an attempt to hide anything. The edit history confirms the original content was always present. Apologies for the confusion. Context: this work is part of my PhD research on 1-day vulnerability propagation across forks and downstream consumers. Having Kvrocks- specific CVE IDs assigned is important for the academic record of this study, and ASF Security has confirmed they plan to coordinate with the Kvrocks team to publish those IDs. Thank you and Alan for the public engagement on the thread -- it strengthens the public coordination record significantly. Best, Jincheng Yang Xidian University
