Vulnerability GO-2026-6356
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
4 hours ago
September 15, 2026 at 06:39 PM UTC
Missing authorization on vttablet /debug/vrlog in vitess.io/vitess
v0.7.0 - v0.23.5
v0.7.0 - v0.23.5
Summary
Missing authorization on vttablet /debug/vrlog in vitess.io/vitess
Details
The vttablet /debug/vrlog HTTP endpoint streams live VReplication event data, including SQL statements and table row changes, without verifying authorization via acl.CheckAccessHTTP. An unauthenticated actor with network access to the debug endpoint can stream live replicated SQL data.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
28 days ago
Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data
v0.7.0 - v0.24.2 GHSA-mhc4-g3wh-cw7m
v0.7.0 - v0.24.2 GHSA-mhc4-g3wh-cw7m
Unknown
6 months ago
Vitess users can gain unauthorized access to production deployment environments in vitess.io/vitess
v0.7.0 - v0.22.3 GO-2026-4567
v0.7.0 - v0.22.3 GO-2026-4567
Unknown
6 months ago
Vitess users with backup storage access can write to arbitrary file paths in vitess.io/vitess
v0.7.0 - v0.22.3 GO-2026-4570
v0.7.0 - v0.22.3 GO-2026-4570
Critical
6 months ago
Vitess users with backup storage access can write to arbitrary file paths on restore
v0.7.0 - v0.22.3 and v0.23.0-rc1 - v0.23.2 GHSA-r492-hjgh-c9gw
v0.7.0 - v0.22.3 and v0.23.0-rc1 - v0.23.2 GHSA-r492-hjgh-c9gw
High Risk
6 months ago
Vitess users with backup storage access can gain unauthorized access to production deployment environments
v0.7.0 - v0.23.2 GHSA-8g8j-r87h-p36x
v0.7.0 - v0.23.2 GHSA-8g8j-r87h-p36x
Impacted packages
Timeline
Published
4 hours ago
September 15, 2026 at 06:39 PM UTC
Last Modified
4 hours ago
September 15, 2026 at 07:00 PM UTC