Executive brief
A vulnerability exists in Oracle MySQL Server and MySQL Cluster within the JSON Duality component. This flaw allows an authorized user with high-level administrative privileges to remotely crash the database service or cause it to hang. Such an attack results in a complete denial of service, preventing legitimate users and applications from accessing critical data and disrupting business operations.
Technical details
This vulnerability affects the 'Server: JSON Duality' component of Oracle MySQL Server and MySQL Cluster. It is classified as a denial-of-service (DoS) vulnerability that can be triggered remotely over multiple protocols. Exploitation requires 'High' privileges (PR:H), meaning the attacker must already have significant access to the database environment. Once authenticated, the attacker can send specific requests that cause the server to hang or crash repeatedly. The issue is present in versions 9.7.0 through 9.7.1 of both MySQL Server and MySQL Cluster. Oracle has addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle MySQL Server 9.7.0-9.7.1
- Oracle MySQL Cluster 9.7.0-9.7.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date