
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61108 is a Denial of Service vulnerability in the GIS (Geographic Information System) component of Oracle MySQL Server and MySQL Cluster. It affects MySQL Server and MySQL Cluster versions 9.7.0 and 9.7.1. The vulnerability was disclosed on July 21, 2026, as part of Oracle's Critical Patch Update (CPU) for July 2026, and was reported by researcher vnth4nhnt of CyStack. It carries a CVSS v3.1 base score of 6.5 (Medium) (Oracle CPU Jul 2026).
The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), indicating that the GIS component fails to properly limit resource usage when processing certain inputs. A low-privileged attacker with network access can exploit this flaw over multiple protocols (e.g., MySQL protocol and its variants) without requiring user interaction or special configuration. Successful exploitation causes the MySQL Server or MySQL Cluster process to hang or crash repeatedly. The attack pattern aligns with CAPEC-492 (Regular Expression Exponential Blowup) and CAPEC-147 (XML Ping of the Death), suggesting the root cause may involve pathological input processing within GIS functionality (Oracle CPU Jul 2026).
Successful exploitation results in a complete Denial of Service (DoS) of the affected MySQL Server or MySQL Cluster instance, causing it to hang or crash in a frequently repeatable manner. There is no impact on confidentiality or integrity — the vulnerability is purely an availability issue. Organizations relying on affected MySQL versions for critical database operations could experience sustained service outages if an authenticated low-privileged user (e.g., a database account with minimal permissions) triggers the flaw (Oracle CPU Jul 2026).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Oracle CPU Jul 2026). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.0029 (0.29%), indicating a low probability of exploitation in the near term. The vulnerability requires low privileges (a valid database account) and no user interaction, making it relatively straightforward to trigger once access is obtained, but the authentication requirement limits opportunistic exploitation.
ST_* or geometry processing functions) with input designed to trigger uncontrolled resource consumption — such as pathologically complex geometry objects or inputs that cause exponential processing.mysqld.err or equivalent) showing repeated crashes, assertion failures, or abnormal termination events originating from GIS/spatial processing functions; entries referencing ST_* or geometry-related stack traces.mysqld process; high CPU or memory consumption by mysqld immediately before a crash, particularly tied to spatial query execution.mysqld crashes in the MySQL data directory or system core dump location, potentially containing GIS-related stack frames.Oracle has released patches for this vulnerability as part of the July 2026 Critical Patch Update. Users should upgrade MySQL Server and MySQL Cluster beyond version 9.7.1 to a patched release as soon as possible. As a temporary workaround, restrict network access to the MySQL server to only trusted clients and applications, and limit database account privileges to reduce the attack surface. Oracle strongly recommends applying the CPU patches without delay rather than relying on network-level controls as a long-term solution (Oracle CPU Jul 2026).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."