Executive brief
A vulnerability in the replication component of Oracle MySQL Server and MySQL Cluster could allow an attacker to crash the database service. This issue affects the availability of the database, potentially leading to service outages or repeated downtime. To exploit this, an attacker would already need high-level administrative privileges and network access to the system.
Technical details
This vulnerability is located in the Server: Replication component of Oracle MySQL Server and MySQL Cluster. It is classified as a denial-of-service (DoS) vulnerability that can result in a hang or a frequently repeatable crash of the affected service. Exploitation requires a high-privileged attacker (PR:H) with network access via multiple protocols. The attack complexity is considered high (AC:H), suggesting that successful exploitation may depend on specific configurations or timing. Affected versions include MySQL Server 8.4.x and 9.7.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.7.x.
Affected products
- Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
- Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date