Junglewise Threat Intelligence

CVE-2026-61109: Oracle MySQL Server and Cluster denial of service in JSON component

CVE-2026-61109 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the JSON component of Oracle MySQL Server and MySQL Cluster can allow an attacker to crash the database service. This could lead to a complete denial of service, preventing applications and users from accessing critical data. An attacker only needs low-level access to the network and basic user credentials to trigger this issue.

Technical details

A vulnerability in the Server: JSON component of Oracle MySQL Server and MySQL Cluster allows for a denial of service (DoS). The flaw is easily exploitable by a low-privileged attacker with network access via multiple protocols. Successful exploitation results in the unauthorized ability to cause a hang or a frequently repeatable crash of the MySQL instance. Affected versions include MySQL Server 8.4.0-8.4.10 and 9.7.0-9.7.1, as well as MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. The vulnerability is tracked as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats