Executive brief
A vulnerability in the Optimizer component of Oracle MySQL Server and MySQL Cluster can allow an attacker to disrupt database services. By sending specific requests, a user with basic login credentials can cause the database to hang or crash repeatedly. This results in a complete denial of service, preventing legitimate users and applications from accessing critical data.
Technical details
This vulnerability exists in the Server: Optimizer component of Oracle MySQL Server and MySQL Cluster. It is classified as a denial-of-service (DoS) vulnerability that is easily exploitable by a low-privileged attacker with network access via multiple protocols. Successful exploitation allows the attacker to cause a hang or a frequently repeatable crash of the server instance. The flaw affects MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.
Affected products
- Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
- Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date