PatchSiren

vitessio CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM vitessio CVE published 2026-08-18

CVE-2026-65959

CVE-2026-65959 is a medium-severity vulnerability in Vitess, a database clustering system for horizontal scaling of MySQL. The vulnerability exists in versions 24.0.2 and earlier, where the /debug/vrlog endpoint allows a remote caller to bypass the configured security policy and stream VrLogStats data, including literal SQL statements and bound application values from certain workflows.