Executive brief
A vulnerability exists in the Optimizer component of Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. A high-privileged attacker with network access can exploit this flaw to cause the database to hang or crash repeatedly. This results in a complete denial-of-service, preventing legitimate users and applications from accessing critical data.
Technical details
This vulnerability is located in the Server: Optimizer component of Oracle MySQL Server and MySQL Cluster. It is classified as a denial-of-service (DoS) flaw that can be triggered by a high-privileged attacker with network access via multiple protocols. Successful exploitation allows the attacker to cause a frequently repeatable crash or a system hang, impacting the availability of the database. The issue affects versions 9.7.0 through 9.7.1 of both MySQL Server and MySQL Cluster. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.
Affected products
- Oracle MySQL Server 9.7.0-9.7.1
- Oracle MySQL Cluster 9.7.0-9.7.1
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
- 2026-07-21: disclosed: NVD published the CVE record.