Executive brief
A vulnerability in the replication component of Oracle MySQL Server and MySQL Cluster could allow an attacker to disrupt database services. If exploited, the database may hang or crash repeatedly, leading to a complete denial of service for applications relying on the data. This issue requires high-level administrative privileges to exploit and is considered difficult to execute.
Technical details
This vulnerability affects the Replication component of MySQL Server and MySQL Cluster. It is classified as a denial of service (DoS) flaw that can be triggered by a high-privileged attacker with network access via multiple protocols. Exploitation is considered difficult (High Attack Complexity) but can result in a complete loss of availability by causing the server to hang or crash repeatedly. Affected versions include MySQL Server 8.4.x and 9.7.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.7.x. Users are advised to consult the Oracle July 2026 Critical Patch Update for remediation details.
Affected products
- Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
- Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date