Description
Vulnerability in Oracle GoldenGate (component: Receiver Service Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Oracle GoldenGate Receiver Service executable permits a low‑privileged attacker with network access via HTTP to cause the service to hang or crash repeatedly, resulting in a complete denial of service. The attack does not expose confidentiality or integrity weaknesses; the primary impact is on availability, as evidenced by the CVSS 3.1 vector indicating an availability impact with no impact to confidentiality or integrity.

Affected Systems

Oracle GoldenGate versions from 19.1.0.0.0 to 19.30.0.0, 21.3 to 21.21, and 23.4 to 23.26.1 are affected. These versions run the Receiver Service component that accepts HTTP connections, and the vulnerability is present only in the specified releases.

Risk and Exploitability

The CVSS Base Score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests the probability of exploitation is very low at the time of analysis and it is not listed in the CISA KEV catalog. The likely attack vector is via an external network that can reach the GoldenGate HTTP endpoint; a low privileged attacker does not need elevated system privileges, but does need network connectivity to the Receiver Service.

Generated by OpenCVE AI on August 2, 2026 at 22:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle GoldenGate patch that resolves the Receiver Service denial‑of‑service flaw, as published in the Oracle Security Alerts and install it using the vendor's upgrade procedures.
  • After installing the patch, restart the GoldenGate Receiver Service and verify that the HTTP endpoint remains functional or is disabled according to your security policy.
  • In the meantime, block or restrict the HTTP port used by the Receiver Service (default or configured) with firewall rules or GoldenGate configuration changes to prevent external access until the patch is applied.

Generated by OpenCVE AI on August 2, 2026 at 22:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via HTTP in Oracle GoldenGate Receiver Service

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Network‑based Low‑Privilege DoS via Oracle GoldenGate Receiver Service HTTP
Weaknesses CWE-284
CWE-770

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Network‑based Low‑Privilege DoS via Oracle GoldenGate Receiver Service HTTP
Weaknesses CWE-284
CWE-770

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle GoldenGate (component: Receiver Service Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle goldengate
CPEs cpe:2.3:a:oracle:goldengate:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle goldengate
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Goldengate
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:28:26.061Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60399

cve-icon Vulnrichment

Updated: 2026-07-24T16:28:03.085Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption