Executive brief
A vulnerability in Oracle MySQL Router can allow an unauthenticated attacker to remotely disable the service. MySQL Router is a middleware component used to manage traffic between applications and database clusters. If exploited, this could lead to a complete denial of service, preventing applications from connecting to their databases and disrupting business operations.
Technical details
A vulnerability in the 'Router: General' component of Oracle MySQL Router (versions 8.4.x and 9.x) allows for uncontrolled resource consumption (CWE-400). An unauthenticated attacker with network access via TLS can exploit this flaw to cause a frequently repeatable crash or a permanent hang of the service. The attack is considered easily exploitable and does not require user interaction or elevated privileges. Successful exploitation results in a complete loss of availability for the MySQL Router instance. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle MySQL Router 8.4.0 - 8.4.9, 9.0.0 - 9.7.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory