# MySQL CVE's affecting current versions of percona pxc images

**URL:** <https://forums.percona.com/t/mysql-cves-affecting-current-versions-of-percona-pxc-images/37020>\
**Category:** Percona XtraDB Cluster 8.x\
**Created:** [March 3, 2025, 12:22pm UTC](https://forums.percona.com/t/mysql-cves-affecting-current-versions-of-percona-pxc-images/37020 "2025-03-03T12:22:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![svkvk](https://avatars.discourse-cdn.com/v4/letter/s/439d5e/32.png) [@svkvk](https://forums.percona.com/u/svkvk)\
**Post date:** [March 3, 2025, 12:22pm UTC](https://forums.percona.com/t/mysql-cves-affecting-current-versions-of-percona-pxc-images/37020/1 "2025-03-03T12:22:04Z")

</div>

Hello,

According to oracle all the currently available pxc images are affected by CVE’s:

[Oracle Critical Patch Update Advisory - January 2025](https://www.oracle.com/security-alerts/cpujan2025.html)

I was wondering if there is any new Percona certified xtradb cluster image on the way or a fix for these CVE’s affecting it? The current latest version is percona/percona-xtradb-cluster:8.0.39-30.1

[Percona certified images - Percona Operator for MySQL](https://docs.percona.com/percona-operator-for-mysql/pxc/images.html)

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [March 3, 2025, 8:05pm UTC](https://forums.percona.com/t/mysql-cves-affecting-current-versions-of-percona-pxc-images/37020/2 "2025-03-03T20:05:19Z")

</div>

[https://hub.docker.com/r/percona/percona-xtradb-cluster/tags](https://hub.docker.com/r/percona/percona-xtradb-cluster/tags)

8.0.40 is the latest version, which should include fixes for these CVEs based on upstream.

---

<div class="post-metadata">

**Author:** ![svkvk](https://avatars.discourse-cdn.com/v4/letter/s/439d5e/32.png) [@svkvk](https://forums.percona.com/u/svkvk)\
**Post date:** [March 10, 2025, 9:00am UTC](https://forums.percona.com/t/mysql-cves-affecting-current-versions-of-percona-pxc-images/37020/3 "2025-03-10T09:00:56Z")

</div>

Thank you matthewd for the quick response and glad to see the cve’s are addressed. I have another question. 8.0.40 is not yet in the percona certified images list: [Percona certified images - Percona Operator for MySQL](https://docs.percona.com/percona-operator-for-mysql/pxc/images.html). I also couldnt find what it means that an image is certified. Should i hold off on upgrading untill 8.0.40 is certified?
