Junglewise Threat Intelligence

CVE-2026-61108: Oracle MySQL Server denial of service in GIS component

CVE-2026-61108 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the GIS component of Oracle MySQL Server and MySQL Cluster allows an attacker to crash the database service. This can lead to a complete denial of service, preventing applications and users from accessing critical data. An attacker only needs low-level access to the network and basic user credentials to trigger this instability.

Technical details

A vulnerability exists in the Geographic Information System (GIS) component of Oracle MySQL Server and MySQL Cluster. The flaw is easily exploitable by a low-privileged attacker with network access via multiple protocols. Successful exploitation allows the attacker to cause a frequently repeatable crash or a complete hang of the server, resulting in a total loss of availability. The issue affects versions 9.7.0 and 9.7.1 of both the standalone Server and Cluster products. No user interaction is required for exploitation.

Affected products

  • Oracle MySQL Server 9.7.0-9.7.1
  • Oracle MySQL Cluster 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update July 2026

References

Related threats