vitess.io/vitess vulnerabilities
CVEs whose affected-version data names the vitess.io/vitess package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-65959Medium· 5.3Vitess is a database clustering system for horizontal scaling of MySQL
Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() wi…
▾ Sunlitvitess · vitess.io/vitessEPSS 0.39%via NVD
CVE-2024-53257Medium· 4.9Vitess allows HTML injection in /debug/querylogz & /debug/env
Vitess allows HTML injection in /debug/querylogz & /debug/env
▾ Sunlitvitess · vitess.io/vitessEPSS 0.44%via OSV
CVE-2024-32886Medium· 4.9Vitess vulnerable to infinite memory consumption and vtgate crash
Vitess vulnerable to infinite memory consumption and vtgate crash
▾ Sunlitvitessio · github.com/vitessio/vitessEPSS 0.75%via OSV
CVE-2023-29194Medium· 4.1vitess allows users to create keyspaces that can deny access to already existing keyspaces
vitess allows users to create keyspaces that can deny access to already existing keyspaces
▾ Sunlitvitess · vitess.io/vitessEPSS 0.78%via OSV