Junglewise Threat Intelligence

CVE-2026-60718: Oracle MySQL Server denial of service in JSON component

CVE-2026-60718 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle MySQL Server and MySQL Cluster within the JSON processing component. An attacker with basic user permissions can remotely cause the database to hang or crash repeatedly. This results in a denial-of-service, preventing legitimate users and applications from accessing critical data and disrupting business operations.

Technical details

This vulnerability is located in the Server: JSON component of Oracle MySQL Server and MySQL Cluster. It is classified as a denial-of-service (DoS) flaw that can be triggered by a low-privileged attacker with network access via multiple protocols. Successful exploitation allows the attacker to cause a complete hang or a frequently repeatable crash of the database instance. The vulnerability has a CVSS 3.1 base score of 6.5, primarily impacting availability. Affected versions are 9.7.0 and 9.7.1 for both MySQL Server and MySQL Cluster.

Affected products

  • Oracle MySQL Server 9.7.0-9.7.1
  • Oracle MySQL Cluster 9.7.0-9.7.1

Timeline

  • 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update containing this CVE.
  • 2026-07-21: disclosed: NVD published the vulnerability details.

References

Related threats