CVE-2024-32886: Vitessio Vitess

Medium severity, CVSS 4.9. EPSS: 0.8% chance of exploitation in the next 30 days.

Vitess is a database clustering system for horizontal scaling of MySQL. When executing the following simple query, the `vtgate` will go into an endless loop that also keeps consuming memory and eventually will run out of memory. This vulnerability is fixed in 19.0.4, 18.0.5, and 17.0.7.

Affected products

  • Vitessio Vitess: before 17.0.7 (fixed in 17.0.7); from 18.0.0, before 18.0.5 (fixed in 18.0.5); from 19.0.0, before 19.0.4 (fixed in 19.0.4)

Published 2024-05-08. Last modified 2026-06-17.