Junglewise Threat Intelligence

CVE-2026-46863: Oracle MySQL denial of service in Connection Handling

CVE-2026-46863 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in Oracle MySQL Server and MySQL Cluster could allow an attacker to remotely crash the database service. This component is responsible for managing incoming connections to the database. If exploited, the database may become unresponsive or shut down completely, leading to a total loss of service for applications and users relying on the data.

Technical details

A vulnerability exists in the 'Server: Connection Handling' component of Oracle MySQL Server and MySQL Cluster. The flaw is classified as uncontrolled resource consumption (CWE-400), which allows an unauthenticated attacker with network access via multiple protocols to trigger a denial-of-service (DoS) condition. Successful exploitation can result in a complete hang or a frequently repeatable crash of the affected database instance. The vulnerability is considered easily exploitable as it requires no special privileges or user interaction. Affected versions include MySQL Server 8.4.x and 9.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.x.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.9, 9.0.0-9.7.0
  • Oracle MySQL Cluster 8.0.11-8.0.46, 8.4.0-8.4.9, 9.0.0-9.7.0

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats