Description
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker with network access to a MySQL Connector/C++ instance to repeatedly trigger a hang or crash, effectively denying service. It is identified as CWE-400 and results in a high availability impact, but it does not provide confidentiality or integrity compromise. Successful exploitation allows the attacker to make the connector become unresponsive.

Affected Systems

Oracle MySQL Connectors, specifically the Connector/C++ component versions 9.7.0 through 9.7.1 released by Oracle Corporation.

Risk and Exploitability

The base CVSS score of 7.5 indicates a high severity availability risk. The EPSS score of less than 1% suggests that exploitation is unlikely but not impossible, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is network-based, requiring no authentication, meaning any host that can reach the connector over supported protocols can attempt the denial of service.

Generated by OpenCVE AI on August 12, 2026 at 12:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to a later release that contains the fix for MySQL Connector/C++ 9.7.x.
  • If an upgrade cannot be performed immediately, block unauthenticated access to the connector by configuring firewalls or network segmentation so that only trusted hosts can communicate with the service.
  • Implement monitoring for service responsiveness and automate restarts or apply application‑level timeout settings to recover from hangs or crashes quickly.

Generated by OpenCVE AI on August 12, 2026 at 12:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network-Based Denial of Service in Oracle MySQL Connector/C++ 9.7.x

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network-Based Denial of Service in Oracle MySQL Connector/C++ 9.7.x

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Connector/C++ Crash in Oracle MySQL Connectors 9.7.0-9.7.1
Weaknesses CWE-770

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Connector/C++ Crash in Oracle MySQL Connectors 9.7.0-9.7.1
Weaknesses CWE-770

Tue, 28 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title MySQL Connector/C++ Denial of Service via Unauthenticated Network Access
Weaknesses CWE-770

Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title MySQL Connector/C++ Denial of Service via Unauthenticated Network Access
Weaknesses CWE-770

Thu, 23 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle mysql Connector/c
Oracle mysql Connectors
Vendors & Products Oracle mysql Connector/c
Oracle mysql Connectors

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle mysql Connector\/c\+\+
CPEs cpe:2.3:a:oracle:mysql_connector\/c\+\+:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Connector\/c\+\+
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Mysql Connector/c Mysql Connector\/c\+\+ Mysql Connectors
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:06:08.886Z

Reserved: 2026-07-08T15:51:40.518Z

Link: CVE-2026-60180

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:18.960

Modified: 2026-08-06T18:17:12.320

Link: CVE-2026-60180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:15:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption