Vulnerability GO-2026-6356

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
4 hours ago
September 15, 2026 at 06:39 PM UTC
Missing authorization on vttablet /debug/vrlog in vitess.io/vitess
v0.7.0 - v0.23.5
v0.7.0 - v0.23.5

Summary

Missing authorization on vttablet /debug/vrlog in vitess.io/vitess

Details

The vttablet /debug/vrlog HTTP endpoint streams live VReplication event data, including SQL statements and table row changes, without verifying authorization via acl.CheckAccessHTTP. An unauthenticated actor with network access to the debug endpoint can stream live replicated SQL data.

Impacted packages

Timeline

Published
4 hours ago
September 15, 2026 at 06:39 PM UTC
Last Modified
4 hours ago
September 15, 2026 at 07:00 PM UTC