
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-46863 is a Denial of Service vulnerability in the Server: Connection Handling component of Oracle MySQL Server and MySQL Cluster. It was disclosed on June 16, 2026, as part of Oracle's Critical Security Patch Update (CSPU). Affected versions include MySQL Server 8.4.0–8.4.9 and 9.0.0–9.7.0, and MySQL Cluster 8.0.11–8.0.46, 8.4.0–8.4.9, and 9.0.0–9.7.0. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Oracle Advisory). The vulnerability was reported to Oracle by researchers 4ra1n, pyn3rd, and unam4 (Oracle Advisory).
The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), residing in the connection handling subsystem of MySQL Server and MySQL Cluster. An unauthenticated remote attacker can exploit this flaw by sending specially crafted requests over multiple supported protocols, causing the server to consume excessive resources and ultimately hang or crash. No authentication or user interaction is required, and attack complexity is low, making it straightforward to trigger. The associated CAPEC patterns include CAPEC-147 (XML Ping of the Death) and CAPEC-492 (Regular Expression Exponential Blowup), suggesting the root cause may involve malformed or resource-intensive input during connection establishment (Oracle Advisory).
Successful exploitation results in a complete denial of service — the MySQL Server or MySQL Cluster instance will hang or crash in a frequently repeatable manner, causing sustained service unavailability. There is no confidentiality or integrity impact; the vulnerability is purely an availability issue. Given that MySQL is commonly used as a backend for critical applications, a successful attack could disrupt dependent services and applications at scale (Oracle Advisory).
Oracle has released patches addressing this vulnerability as part of the June 2026 Critical Security Patch Update. Administrators should upgrade MySQL Server to a version beyond 8.4.9 or 9.7.0, and MySQL Cluster to a version beyond 8.0.46, 8.4.9, or 9.7.0, depending on their deployment branch. As interim mitigations, apply network segmentation to restrict MySQL port access (default TCP 3306/33060) to trusted hosts only, and implement rate limiting on connection attempts to reduce exposure. Oracle strongly recommends applying patches as soon as possible rather than relying on network-level workarounds (Oracle Advisory).
Ubuntu issued security notices USN-8457-1 and USN-8457-2 addressing this and related MySQL vulnerabilities for Ubuntu users, indicating downstream Linux distribution uptake of the patch (Ubuntu USN-8457-1, Ubuntu USN-8457-2). Tenable published multiple Nessus detection plugins (IDs 321532, 321533, 321535, 321537, 321654, 322263) to identify vulnerable systems. No significant public researcher commentary or social media discussion has been observed beyond standard patch tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."