Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-61108
MySQL vulnerability analysis and mitigation

Overview

CVE-2026-61108 is a Denial of Service vulnerability in the GIS (Geographic Information System) component of Oracle MySQL Server and MySQL Cluster. It affects MySQL Server and MySQL Cluster versions 9.7.0 and 9.7.1. The vulnerability was disclosed on July 21, 2026, as part of Oracle's Critical Patch Update (CPU) for July 2026, and was reported by researcher vnth4nhnt of CyStack. It carries a CVSS v3.1 base score of 6.5 (Medium) (Oracle CPU Jul 2026).

Technical details

The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), indicating that the GIS component fails to properly limit resource usage when processing certain inputs. A low-privileged attacker with network access can exploit this flaw over multiple protocols (e.g., MySQL protocol and its variants) without requiring user interaction or special configuration. Successful exploitation causes the MySQL Server or MySQL Cluster process to hang or crash repeatedly. The attack pattern aligns with CAPEC-492 (Regular Expression Exponential Blowup) and CAPEC-147 (XML Ping of the Death), suggesting the root cause may involve pathological input processing within GIS functionality (Oracle CPU Jul 2026).

Impact

Successful exploitation results in a complete Denial of Service (DoS) of the affected MySQL Server or MySQL Cluster instance, causing it to hang or crash in a frequently repeatable manner. There is no impact on confidentiality or integrity — the vulnerability is purely an availability issue. Organizations relying on affected MySQL versions for critical database operations could experience sustained service outages if an authenticated low-privileged user (e.g., a database account with minimal permissions) triggers the flaw (Oracle CPU Jul 2026).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Oracle CPU Jul 2026). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.0029 (0.29%), indicating a low probability of exploitation in the near term. The vulnerability requires low privileges (a valid database account) and no user interaction, making it relatively straightforward to trigger once access is obtained, but the authentication requirement limits opportunistic exploitation.

Exploitation steps

  1. Obtain low-privileged database credentials: Acquire any valid MySQL user account with network access to the target MySQL Server or MySQL Cluster instance running versions 9.7.0 or 9.7.1.
  2. Connect to the target: Establish a connection to the MySQL server using a standard MySQL client or connector over any supported protocol (e.g., TCP/IP).
  3. Craft a malicious GIS query: Formulate a SQL query targeting the GIS component (e.g., using spatial functions such as ST_* or geometry processing functions) with input designed to trigger uncontrolled resource consumption — such as pathologically complex geometry objects or inputs that cause exponential processing.
  4. Submit the query: Execute the crafted query against the server. The GIS component fails to limit resource usage, causing the MySQL server process to hang or crash.
  5. Repeat for persistent DoS: Because the crash is "frequently repeatable," the attacker can re-trigger the condition after any automatic restart, maintaining a sustained denial of service (Oracle CPU Jul 2026).

Indicators of compromise

  • Logs: MySQL error log (mysqld.err or equivalent) showing repeated crashes, assertion failures, or abnormal termination events originating from GIS/spatial processing functions; entries referencing ST_* or geometry-related stack traces.
  • Process: Unexpected termination and restart of the mysqld process; high CPU or memory consumption by mysqld immediately before a crash, particularly tied to spatial query execution.
  • Network: Repeated connections from the same low-privileged client account issuing spatial/GIS queries in rapid succession; unusual query patterns involving geometry functions in general query logs.
  • File System: Core dump files generated by mysqld crashes in the MySQL data directory or system core dump location, potentially containing GIS-related stack frames.

Mitigation and workarounds

Oracle has released patches for this vulnerability as part of the July 2026 Critical Patch Update. Users should upgrade MySQL Server and MySQL Cluster beyond version 9.7.1 to a patched release as soon as possible. As a temporary workaround, restrict network access to the MySQL server to only trusted clients and applications, and limit database account privileges to reduce the attack surface. Oracle strongly recommends applying the CPU patches without delay rather than relying on network-level controls as a long-term solution (Oracle CPU Jul 2026).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

mysql-9.7: 9.7.2-1

Fixed

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

Not Affected

SourceThis report was generated using AI

Related MySQL vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63385CRITICAL9.2
  • MySQL logoMySQL
  • libevent
NoYesAug 20, 2026
CVE-2026-63384HIGH8.7
  • MySQL logoMySQL
  • libevent-debuginfo
NoYesAug 20, 2026
CVE-2026-63383HIGH8.7
  • MySQL logoMySQL
  • libevent-doc
NoYesAug 20, 2026
CVE-2026-63388HIGH8.4
  • MySQL logoMySQL
  • libevent
NoYesAug 20, 2026
CVE-2026-63387HIGH7
  • MySQL logoMySQL
  • libevent2
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management