Executive brief
A vulnerability exists in the Optimizer component of Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. An attacker with basic user permissions can remotely trigger a system hang or a repeated crash, leading to a complete denial of service. This can disrupt business operations by making critical data and applications unavailable to legitimate users.
Technical details
This vulnerability is located in the Server: Optimizer component of Oracle MySQL. It is classified as a denial of service (DoS) flaw that can be triggered by a low-privileged attacker with network access via multiple protocols. Successful exploitation allows the attacker to cause a frequently repeatable crash or a system hang, impacting the availability of the MySQL Server or MySQL Cluster. The vulnerability requires basic authentication (PR:L) but no user interaction. Affected versions include MySQL Server and MySQL Cluster 9.7.0 and 9.7.1.
Affected products
- Oracle MySQL Server 9.7.0-9.7.1
- Oracle MySQL Cluster 9.7.0-9.7.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory