Executive brief
A vulnerability exists in Oracle MySQL Server and MySQL Cluster within the JSON Duality component. An attacker with high-level administrative privileges can remotely trigger a system hang or a repeated crash. This results in a complete denial of service, making the database unavailable for legitimate business operations and applications.
Technical details
This vulnerability affects the Server: JSON Duality component of Oracle MySQL Server and MySQL Cluster versions 9.7.0 through 9.7.1. It is classified as a denial of service (DoS) flaw that can be triggered by a high-privileged attacker with network access via multiple protocols. Successful exploitation allows the attacker to cause a hang or a frequently repeatable crash of the server instance. The attack is considered easily exploitable (low attack complexity) but requires high administrative privileges (PR:H). The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle MySQL Server 9.7.0-9.7.1
- Oracle MySQL Cluster 9.7.0-9.7.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory