vitess.io/vitess
Go7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting vitess.io/vitesspage 1 of 1
- CVE-2023-29194MEDIUMCVSS 4.1EG 4.1fixed in 0.16.12023-04-14
Vitess is a database clustering system for horizontal scaling of MySQL. Users can either intentionally or inadvertently create a keyspace containing `/` characters such that from that point on, anyone who tries to view keyspaces from VTAdm…
- CVE-2023-29195MEDIUMCVSS 4.1EG 4.1fixed in 0.16.22023-05-11
Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16.0.2, users can either intentionally or inadvertently create a shard containing `/` characters from VTAdmin such that f…
- CVE-2024-32886MEDIUMCVSS 4.9EG 4.9fixed in 0.17.7, 0.18.5 or 0.19.4, by version range2024-05-08
Vitess is a database clustering system for horizontal scaling of MySQL. When executing the following simple query, the `vtgate` will go into an endless loop that also keeps consuming memory and eventually will run out of memory. This vulne…
- CVE-2024-53257MEDIUMCVSS 4.9EG 4.9fixed in 0.21.1, 0.20.4 or 0.19.8, by version range2024-12-03
Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vtgate and vttablet do not properly escape user input. The result is that queries executed by Vitess can write HTML into …
- CVE-2026-27965CRITICALCVSS 9.9EG 9.9fixed in 0.22.4 or 0.23.3, by version range2026-02-26
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that arbi…
- CVE-2026-27969HIGHCVSS 8.8EG 8.8fixed in 0.23.3 or 0.22.4, by version range2026-02-26
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that file…
- CVE-2026-65959MEDIUMCVSS 5.3EG 5.3fixed in 0.23.6 or 0.24.3, by version range2026-08-18
Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() with…
Check whether vitess.io/vitess is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for vitess.io/vitess CVEs against the assets you own.
Book a Demo →