Description
Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle MySQL Router (CWE-400) allows an unauthenticated attacker with network access over HTTP to trigger a crash that can be repeated to cause a complete denial of service. The flaw is easily exploitable and results in availability damage, with no impact on confidentiality or integrity.

Affected Systems

Oracle Corporation’s MySQL Router is impacted. Affected releases include 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 reflects a high availability impact. The EPSS score is below 1%, indicating a low probability of widespread exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack path is an unauthenticated HTTP request sent to the router, which is straightforward to construct and does not require privileged credentials.

Generated by OpenCVE AI on August 4, 2026 at 17:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MySQL Router to a version that contains the vendor fix for the vulnerability.
  • Restrict external network traffic to the MySQL Router by blocking or firewalling the HTTP ports for untrusted hosts.
  • Continuously monitor the router’s logs for repeated crash patterns and schedule the service for automatic restart as a containment measure.

Generated by OpenCVE AI on August 4, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Denial of Service in MySQL Router

Tue, 28 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Remote HTTP Denial of Service in Oracle MySQL Router
Weaknesses CWE-744

Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Remote HTTP Denial of Service in Oracle MySQL Router
Weaknesses CWE-744

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle mysql Router
CPEs cpe:2.3:a:oracle:mysql_router:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Router
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Mysql Router
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:18:34.907Z

Reserved: 2026-07-08T15:51:40.529Z

Link: CVE-2026-60314

cve-icon Vulnrichment

Updated: 2026-07-23T19:15:30.352Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption