Vitess is a database clustering system for horizontal scaling of MySQL. When executing the following simple query, the `vtgate` will go into an endless loop that also keeps consuming memory and eventually will run out of memory. This vulnerability is fixed in 19.0.4, 18.0.5, and 17.0.7.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1448 | Vitess is a database clustering system for horizontal scaling of MySQL. When executing the following simple query, the `vtgate` will go into an endless loop that also keeps consuming memory and eventually will run out of memory. This vulnerability is fixed in 19.0.4, 18.0.5, and 17.0.7. |
Github GHSA |
GHSA-649x-hxfx-57j2 | Vitess vulnerable to infinite memory consumption and vtgate crash |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T02:20:35.665Z
Reserved: 2024-04-19T14:07:11.231Z
Link: CVE-2024-32886
Updated: 2024-05-09T15:55:43.951Z
Status : Awaiting Analysis
Published: 2024-05-08T14:15:08.310
Modified: 2024-11-21T09:15:56.327
Link: CVE-2024-32886
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:09:38Z
Weaknesses
EUVD
Github GHSA