Executive brief
Oracle GoldenGate, a software suite for real-time data integration and replication, contains a vulnerability in its Receiver Service. An attacker with low-level user credentials can remotely trigger a system hang or a repeated crash over the network. This would result in a complete denial of service, halting critical data synchronization and replication tasks across the enterprise.
Technical details
A vulnerability in the Receiver Service Executable component of Oracle GoldenGate allows a low-privileged attacker with network access via HTTP to compromise the system. The flaw is categorized as easily exploitable and specifically impacts the availability of the service. Successful exploitation enables an attacker to cause a hang or a frequently repeatable crash, leading to a complete denial of service (DoS). The vulnerability affects versions 19.1.0.0.0 through 19.30.0.0, 21.3 through 21.21, and 23.4 through 23.26.1. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle GoldenGate 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.1
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD