GO-2026-6356

    Dashboard / Vulnerabilities / GO-2026-6356

    GO-2026-6356

    Published: 15 Sept 2026Last Modified: 15 Sept 2026

    Summary: Missing authorization on vttablet /debug/vrlog in vitess.io/vitess

    Details: The vttablet /debug/vrlog HTTP endpoint streams live VReplication event data, including SQL statements and table row changes, without verifying authorization via acl.CheckAccessHTTP. An unauthenticated actor with network access to the debug endpoint can stream live replicated SQL data.

    Affected packages

    Package

    Name: vitess.io/vitess

    Purl: pkg:golang/vitess.io/vitess

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.23.6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High