Executive brief
Oracle MySQL Router, a middleware component used to optimize database traffic and high availability, is vulnerable to a remote attack. An unauthenticated attacker can send malicious network traffic to the service to cause it to hang or crash repeatedly. This results in a complete denial of service, preventing applications from connecting to their underlying databases and disrupting business operations.
Technical details
A vulnerability in the 'Router: General' component of Oracle MySQL Router allows for a remote denial of service. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation results in a complete loss of availability by causing the MySQL Router process to hang or crash frequently. Affected versions include 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle MySQL Router 8.4.0-8.4.10, 9.7.0-9.7.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released