CVE-2024-32886

MEDIUM

Vitess < 19.0.4 - Infinite Loop

Title source: rule
STIX 2.1

Description

Vitess is a database clustering system for horizontal scaling of MySQL. When executing the following simple query, the `vtgate` will go into an endless loop that also keeps consuming memory and eventually will run out of memory. This vulnerability is fixed in 19.0.4, 18.0.5, and 17.0.7.

Scores

CVSS v3 4.9
EPSS 0.0010
EPSS Percentile 27.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-835
Status published
Products (5)
vitess.io/vitess 0 - 0.17.7Go
vitessio/vitess 19.0.0 - 19.0.4Go
vitessio/vitess < 17.0.7
vitessio/vitess >= 18.0.0, < 18.0.5
vitessio/vitess >= 19.0.0, < 19.0.4
Published May 08, 2024
Tracked Since Feb 18, 2026