Source: mysql-9.7 Version: 9.7.1-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for mysql-9.7. CVE-2026-46936[0]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: DDL). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a hang or frequently repeatable crash (complete | DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 | (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-47008[1]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: InnoDB). Supported versions that are affected are | MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily | exploitable vulnerability allows high privileged attacker with | network access via multiple protocols to compromise MySQL Server, | MySQL Cluster. Successful attacks of this vulnerability can result | in unauthorized ability to cause a hang or frequently repeatable | crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base | Score 4.9 (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-47012[2]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Optimizer). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a hang or frequently repeatable crash (complete | DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 | (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-47023[3]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Replication). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a hang or frequently repeatable crash (complete | DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 | (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-47052[4]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: InnoDB). Supported versions that are affected are | MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a hang or frequently repeatable crash (complete | DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 | (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-47064[5]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Optimizer). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable | vulnerability allows low privileged attacker with network access via | multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a hang or frequently repeatable crash (complete | DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 | (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60145[6]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Optimizer). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a hang or frequently repeatable crash (complete | DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 | (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60163[7]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Group Replication Plugin). Supported | versions that are affected are MySQL Server: 8.4.0-8.4.10, | 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and | 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated | attacker with logon to the infrastructure where MySQL Server, MySQL | Cluster executes to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in takeover of | MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 8.4 | (Confidentiality, Integrity and Availability impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). CVE-2026-60174[8]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Optimizer). Supported versions that are | affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. | Easily exploitable vulnerability allows low privileged attacker with | network access via multiple protocols to compromise MySQL Server, | MySQL Cluster. Successful attacks of this vulnerability can result | in unauthorized ability to cause a hang or frequently repeatable | crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base | Score 6.5 (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60177[9]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Clone Plugin). Supported versions that | are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL | Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to | exploit vulnerability allows high privileged attacker with network | access via multiple protocols to compromise MySQL Server, MySQL | Cluster. Successful attacks of this vulnerability can result in | unauthorized ability to cause a hang or frequently repeatable crash | (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score | 4.4 (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60178[10]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Clone Plugin). Supported versions that | are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL | Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to | exploit vulnerability allows high privileged attacker with network | access via multiple protocols to compromise MySQL Server, MySQL | Cluster. Successful attacks of this vulnerability can result in | takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 | (Confidentiality, Integrity and Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H). CVE-2026-60181[11]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Configurator). Supported versions that | are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: | 9.7.0-9.7.1. Difficult to exploit vulnerability allows low | privileged attacker with logon to the infrastructure where MySQL | Server, MySQL Cluster executes to compromise MySQL Server, MySQL | Cluster. Successful attacks require human interaction from a person | other than the attacker. Successful attacks of this vulnerability | can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base | Score 6.7 (Confidentiality, Integrity and Availability impacts). | CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H). CVE-2026-60182[12]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Clone Plugin). Supported versions that | are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL | Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to | exploit vulnerability allows high privileged attacker with network | access via multiple protocols to compromise MySQL Server, MySQL | Cluster. Successful attacks of this vulnerability can result in | unauthorized ability to cause a hang or frequently repeatable crash | (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score | 4.4 (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60183[13]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Clone Plugin). Supported versions that | are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL | Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to | exploit vulnerability allows high privileged attacker with logon to | the infrastructure where MySQL Server, MySQL Cluster executes to | compromise MySQL Server, MySQL Cluster. Successful attacks of this | vulnerability can result in takeover of MySQL Server, MySQL Cluster. | CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H). CVE-2026-60184[14]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Replication). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a hang or frequently repeatable crash (complete | DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 | (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60185[15]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Replication). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a hang or frequently repeatable crash (complete | DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 | (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60186[16]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Group Replication Plugin). Supported | versions that are affected are MySQL Server: 8.4.0-8.4.10, | 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and | 9.7.0-9.7.1. Difficult to exploit vulnerability allows high | privileged attacker with network access via multiple protocols to | compromise MySQL Server, MySQL Cluster. Successful attacks of this | vulnerability can result in unauthorized ability to cause a hang or | frequently repeatable crash (complete DOS) of MySQL Server, MySQL | Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS | Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60187[17]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Replication). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a hang or frequently repeatable crash (complete | DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 | (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60188[18]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Replication). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a hang or frequently repeatable crash (complete | DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 | (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60189[19]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Replication). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a hang or frequently repeatable crash (complete | DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 | (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60190[20]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Replication). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a partial denial of service (partial DOS) of MySQL | Server, MySQL Cluster. CVSS 3.1 Base Score 2.2 (Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L). CVE-2026-60191[21]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Replication). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit | vulnerability allows high privileged attacker with logon to the | infrastructure where MySQL Server, MySQL Cluster executes to | compromise MySQL Server, MySQL Cluster. Successful attacks of this | vulnerability can result in unauthorized ability to cause a hang or | frequently repeatable crash (complete DOS) of MySQL Server, MySQL | Cluster. CVSS 3.1 Base Score 4.1 (Availability impacts). CVSS | Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60194[22]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: JSON Duality). Supported versions that | are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: | 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged | attacker with network access via multiple protocols to compromise | MySQL Server, MySQL Cluster. Successful attacks of this | vulnerability can result in unauthorized ability to cause a hang or | frequently repeatable crash (complete DOS) of MySQL Server, MySQL | Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS | Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60195[23]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: JSON Duality). Supported versions that | are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: | 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged | attacker with network access via multiple protocols to compromise | MySQL Server, MySQL Cluster. Successful attacks of this | vulnerability can result in unauthorized ability to cause a hang or | frequently repeatable crash (complete DOS) of MySQL Server, MySQL | Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS | Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60311[24]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Optimizer). Supported versions that are | affected are MySQL Server: 9.0.0-9.7.1; MySQL Cluster: 9.0.0-9.7.1. | Easily exploitable vulnerability allows low privileged attacker with | network access via multiple protocols to compromise MySQL Server, | MySQL Cluster. Successful attacks of this vulnerability can result | in unauthorized ability to cause a hang or frequently repeatable | crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base | Score 6.5 (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60315[25]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: X Plugin). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable | vulnerability allows unauthenticated attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a hang or frequently repeatable crash (complete | DOS) of MySQL Server, MySQL Cluster and unauthorized read access to | a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 | Base Score 8.2 (Confidentiality and Availability impacts). CVSS | Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H). CVE-2026-60316[26]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: X Plugin). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in takeover of | MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.2 | (Confidentiality, Integrity and Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). CVE-2026-60324[27]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Optimizer). Supported versions that are | affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. | Easily exploitable vulnerability allows low privileged attacker with | network access via multiple protocols to compromise MySQL Server, | MySQL Cluster. Successful attacks of this vulnerability can result | in unauthorized ability to cause a hang or frequently repeatable | crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base | Score 6.5 (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60331[28]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Replication). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit | vulnerability allows high privileged attacker with logon to the | infrastructure where MySQL Server, MySQL Cluster executes to | compromise MySQL Server, MySQL Cluster. Successful attacks of this | vulnerability can result in takeover of MySQL Server, MySQL Cluster. | CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H). CVE-2026-60332[29]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Group Replication GCS). Supported | versions that are affected are MySQL Server: 8.4.0-8.4.10, | 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and | 9.7.0-9.7.1. Difficult to exploit vulnerability allows high | privileged attacker with logon to the infrastructure where MySQL | Server, MySQL Cluster executes to compromise MySQL Server, MySQL | Cluster. Successful attacks of this vulnerability can result in | takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 | (Confidentiality, Integrity and Availability impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H). CVE-2026-60585[30]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Replication). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in takeover of | MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 | (Confidentiality, Integrity and Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H). CVE-2026-60718[31]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: JSON). Supported versions that are | affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. | Easily exploitable vulnerability allows low privileged attacker with | network access via multiple protocols to compromise MySQL Server, | MySQL Cluster. Successful attacks of this vulnerability can result | in unauthorized ability to cause a hang or frequently repeatable | crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base | Score 6.5 (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60747[32]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Replication). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable | vulnerability allows unauthenticated attacker with logon to the | infrastructure where MySQL Server, MySQL Cluster executes to | compromise MySQL Server, MySQL Cluster. Successful attacks of this | vulnerability can result in unauthorized ability to cause a hang or | frequently repeatable crash (complete DOS) of MySQL Server, MySQL | Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS | Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). CVE-2026-61081[33]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Performance Schema). Supported versions | that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL | Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily | exploitable vulnerability allows high privileged attacker with | network access via multiple protocols to compromise MySQL Server, | MySQL Cluster. Successful attacks of this vulnerability can result | in unauthorized read access to a subset of MySQL Server, MySQL | Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality | impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N). CVE-2026-61093[34]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Optimizer). Supported versions that are | affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. | Easily exploitable vulnerability allows low privileged attacker with | network access via multiple protocols to compromise MySQL Server, | MySQL Cluster. Successful attacks of this vulnerability can result | in unauthorized ability to cause a hang or frequently repeatable | crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base | Score 6.5 (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). CVE-2026-61094[35]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Replication). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable | vulnerability allows high privileged attacker with network access | via multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in takeover of | MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.2 | (Confidentiality, Integrity and Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). CVE-2026-61096[36]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Pluggable Auth). Supported versions that | are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL | Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to | exploit vulnerability allows unauthenticated attacker with logon to | the infrastructure where MySQL Server, MySQL Cluster executes to | compromise MySQL Server, MySQL Cluster. Successful attacks of this | vulnerability can result in unauthorized update, insert or delete | access to some of MySQL Server, MySQL Cluster accessible data. CVSS | 3.1 Base Score 2.9 (Integrity impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N). CVE-2026-61108[37]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: GIS). Supported versions that are | affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. | Easily exploitable vulnerability allows low privileged attacker with | network access via multiple protocols to compromise MySQL Server, | MySQL Cluster. Successful attacks of this vulnerability can result | in unauthorized ability to cause a hang or frequently repeatable | crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base | Score 6.5 (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). CVE-2026-61109[38]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: JSON). Supported versions that are | affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: | 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable | vulnerability allows low privileged attacker with network access via | multiple protocols to compromise MySQL Server, MySQL Cluster. | Successful attacks of this vulnerability can result in unauthorized | ability to cause a hang or frequently repeatable crash (complete | DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 | (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). CVE-2026-61128[39]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Optimizer). Supported versions that are | affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. | Easily exploitable vulnerability allows high privileged attacker | with network access via multiple protocols to compromise MySQL | Server, MySQL Cluster. Successful attacks of this vulnerability can | result in unauthorized ability to cause a hang or frequently | repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS | 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-61144[40]: | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle | MySQL (component: Server: Optimizer). Supported versions that are | affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. | Easily exploitable vulnerability allows high privileged attacker | with network access via multiple protocols to compromise MySQL | Server, MySQL Cluster. Successful attacks of this vulnerability can | result in unauthorized ability to cause a hang or frequently | repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS | 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-46936 https://www.cve.org/CVERecord?id=CVE-2026-46936 [1] https://security-tracker.debian.org/tracker/CVE-2026-47008 https://www.cve.org/CVERecord?id=CVE-2026-47008 [2] https://security-tracker.debian.org/tracker/CVE-2026-47012 https://www.cve.org/CVERecord?id=CVE-2026-47012 [3] https://security-tracker.debian.org/tracker/CVE-2026-47023 https://www.cve.org/CVERecord?id=CVE-2026-47023 [4] https://security-tracker.debian.org/tracker/CVE-2026-47052 https://www.cve.org/CVERecord?id=CVE-2026-47052 [5] https://security-tracker.debian.org/tracker/CVE-2026-47064 https://www.cve.org/CVERecord?id=CVE-2026-47064 [6] https://security-tracker.debian.org/tracker/CVE-2026-60145 https://www.cve.org/CVERecord?id=CVE-2026-60145 [7] https://security-tracker.debian.org/tracker/CVE-2026-60163 https://www.cve.org/CVERecord?id=CVE-2026-60163 [8] https://security-tracker.debian.org/tracker/CVE-2026-60174 https://www.cve.org/CVERecord?id=CVE-2026-60174 [9] https://security-tracker.debian.org/tracker/CVE-2026-60177 https://www.cve.org/CVERecord?id=CVE-2026-60177 [10] https://security-tracker.debian.org/tracker/CVE-2026-60178 https://www.cve.org/CVERecord?id=CVE-2026-60178 [11] https://security-tracker.debian.org/tracker/CVE-2026-60181 https://www.cve.org/CVERecord?id=CVE-2026-60181 [12] https://security-tracker.debian.org/tracker/CVE-2026-60182 https://www.cve.org/CVERecord?id=CVE-2026-60182 [13] https://security-tracker.debian.org/tracker/CVE-2026-60183 https://www.cve.org/CVERecord?id=CVE-2026-60183 [14] https://security-tracker.debian.org/tracker/CVE-2026-60184 https://www.cve.org/CVERecord?id=CVE-2026-60184 [15] https://security-tracker.debian.org/tracker/CVE-2026-60185 https://www.cve.org/CVERecord?id=CVE-2026-60185 [16] https://security-tracker.debian.org/tracker/CVE-2026-60186 https://www.cve.org/CVERecord?id=CVE-2026-60186 [17] https://security-tracker.debian.org/tracker/CVE-2026-60187 https://www.cve.org/CVERecord?id=CVE-2026-60187 [18] https://security-tracker.debian.org/tracker/CVE-2026-60188 https://www.cve.org/CVERecord?id=CVE-2026-60188 [19] https://security-tracker.debian.org/tracker/CVE-2026-60189 https://www.cve.org/CVERecord?id=CVE-2026-60189 [20] https://security-tracker.debian.org/tracker/CVE-2026-60190 https://www.cve.org/CVERecord?id=CVE-2026-60190 [21] https://security-tracker.debian.org/tracker/CVE-2026-60191 https://www.cve.org/CVERecord?id=CVE-2026-60191 [22] https://security-tracker.debian.org/tracker/CVE-2026-60194 https://www.cve.org/CVERecord?id=CVE-2026-60194 [23] https://security-tracker.debian.org/tracker/CVE-2026-60195 https://www.cve.org/CVERecord?id=CVE-2026-60195 [24] https://security-tracker.debian.org/tracker/CVE-2026-60311 https://www.cve.org/CVERecord?id=CVE-2026-60311 [25] https://security-tracker.debian.org/tracker/CVE-2026-60315 https://www.cve.org/CVERecord?id=CVE-2026-60315 [26] https://security-tracker.debian.org/tracker/CVE-2026-60316 https://www.cve.org/CVERecord?id=CVE-2026-60316 [27] https://security-tracker.debian.org/tracker/CVE-2026-60324 https://www.cve.org/CVERecord?id=CVE-2026-60324 [28] https://security-tracker.debian.org/tracker/CVE-2026-60331 https://www.cve.org/CVERecord?id=CVE-2026-60331 [29] https://security-tracker.debian.org/tracker/CVE-2026-60332 https://www.cve.org/CVERecord?id=CVE-2026-60332 [30] https://security-tracker.debian.org/tracker/CVE-2026-60585 https://www.cve.org/CVERecord?id=CVE-2026-60585 [31] https://security-tracker.debian.org/tracker/CVE-2026-60718 https://www.cve.org/CVERecord?id=CVE-2026-60718 [32] https://security-tracker.debian.org/tracker/CVE-2026-60747 https://www.cve.org/CVERecord?id=CVE-2026-60747 [33] https://security-tracker.debian.org/tracker/CVE-2026-61081 https://www.cve.org/CVERecord?id=CVE-2026-61081 [34] https://security-tracker.debian.org/tracker/CVE-2026-61093 https://www.cve.org/CVERecord?id=CVE-2026-61093 [35] https://security-tracker.debian.org/tracker/CVE-2026-61094 https://www.cve.org/CVERecord?id=CVE-2026-61094 [36] https://security-tracker.debian.org/tracker/CVE-2026-61096 https://www.cve.org/CVERecord?id=CVE-2026-61096 [37] https://security-tracker.debian.org/tracker/CVE-2026-61108 https://www.cve.org/CVERecord?id=CVE-2026-61108 [38] https://security-tracker.debian.org/tracker/CVE-2026-61109 https://www.cve.org/CVERecord?id=CVE-2026-61109 [39] https://security-tracker.debian.org/tracker/CVE-2026-61128 https://www.cve.org/CVERecord?id=CVE-2026-61128 [40] https://security-tracker.debian.org/tracker/CVE-2026-61144 https://www.cve.org/CVERecord?id=CVE-2026-61144 Regards, Salvatore

