vitess has 3 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 4.9 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.9
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Weakness classes
Products
- vitess.io/vitess 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-65959Medium· 5.3Vitess is a database clustering system for horizontal scaling of MySQL29CVE-2024-53257Medium· 4.9Vitess allows HTML injection in /debug/querylogz & /debug/env27CVE-2023-29194Medium· 4.1vitess allows users to create keyspaces that can deny access to already existing keyspaces23
vitess vulnerabilities
CVEs affecting vitess, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-65959Medium· 5.3Vitess is a database clustering system for horizontal scaling of MySQL
Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() wi…
▾ Sunlitvitess · vitess.io/vitessEPSS 0.39%via NVD
CVE-2024-53257Medium· 4.9Vitess allows HTML injection in /debug/querylogz & /debug/env
Vitess allows HTML injection in /debug/querylogz & /debug/env
▾ Sunlitvitess · vitess.io/vitessEPSS 0.44%via OSV
CVE-2023-29194Medium· 4.1vitess allows users to create keyspaces that can deny access to already existing keyspaces
vitess allows users to create keyspaces that can deny access to already existing keyspaces
▾ Sunlitvitess · vitess.io/vitessEPSS 0.78%via OSV