# NCSC‑2026‑0032 CVEs affecting PXC 8.4.7‑7.1

**URL:** <https://forums.percona.com/t/ncsc-2026-0032-cves-affecting-pxc-8-4-7-7-1/40348>\
**Category:** Other MySQL® Questions\
**Tags:** percona, new-release\
**Created:** [March 10, 2026, 10:21am UTC](https://forums.percona.com/t/ncsc-2026-0032-cves-affecting-pxc-8-4-7-7-1/40348 "2026-03-10T10:21:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Peters](https://avatars.discourse-cdn.com/v4/letter/p/bc8723/32.png) [@Peters](https://forums.percona.com/u/Peters)\
**Post date:** [March 10, 2026, 10:21am UTC](https://forums.percona.com/t/ncsc-2026-0032-cves-affecting-pxc-8-4-7-7-1/40348/1 "2026-03-10T10:21:09Z")

</div>

Hi Percona team,

We are currently running Percona XtraDB Cluster 8.4.7‑7.1 with the Percona Operator 1.19.0.  
This version is based on Percona Server for MySQL 8.4.7, which itself is based on Oracle MySQL 8.4.7.

According to the **NCSC‑2026‑0032 advisory** , the following MySQL CVEs affect MySQL versions up to 8.4.7:

- CVE‑2026‑21968 – Optimizer DoS via specially crafted queries
- CVE‑2026‑21949 – Optimizer server crash
- CVE‑2026‑21948 – Optimizer DoS
- CVE‑2026‑21941 – Optimizer crash/hang
- CVE‑2026‑21936 – InnoDB Denial of Service
- CVE‑2026‑21964 – Thread Pool crash/hang
- CVE‑2025‑6965 – packaging / dependency issue

My Questions are:

1. Is there a planned release of Percona XtraDB Cluster 8.4.x that includes upstream fixes for these CVEs?
2. Are there any recommended mitigations we can apply in the meantime to reduce risk?

Thank you

---

<div class="post-metadata">

**Author:** ![Wayne\_Leutwyler](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wayne_leutwyler/32/20829_2.png) [@Wayne\_Leutwyler](https://forums.percona.com/u/Wayne_Leutwyler)\
**Post date:** [March 10, 2026, 12:41pm UTC](https://forums.percona.com/t/ncsc-2026-0032-cves-affecting-pxc-8-4-7-7-1/40348/2 "2026-03-10T12:41:07Z")

</div>

> [@Peters](#):
>
> Is there a planned release of Percona XtraDB Cluster 8.4.x that includes upstream fixes for these CVEs?

Percona Server for MySQL **8.4.8-8.1** includes fixes for all the CVEs you listed **except CVE-2025-6965**.

**CVE-2025-6965** is a vulnerability in the **SQLite database engine** , specifically affecting SQLite versions prior to **3.50.2**. Since **Percona Server for MySQL does not use or embed SQLite in its server codebase** , this vulnerability **does not impact Percona Server**.

Therefore:

- **CVE-2026-21936, CVE-2026-21941, CVE-2026-21948, CVE‑2026‑21949, CVE-2026-21964, and CVE-2026-21968** are addressed in **Percona Server for MySQL 8.4.8-8.1**.
- **CVE-2025-6965** is **not applicable** , as it pertains exclusively to **SQLite** and has **no impact on Percona Server**.

---

<div class="post-metadata">

**Author:** ![Peters](https://avatars.discourse-cdn.com/v4/letter/p/bc8723/32.png) [@Peters](https://forums.percona.com/u/Peters)\
**Post date:** [April 8, 2026, 12:27pm UTC](https://forums.percona.com/t/ncsc-2026-0032-cves-affecting-pxc-8-4-7-7-1/40348/3 "2026-04-08T12:27:48Z")

</div>

Hi Wayne,

Thanks for the clarification regarding the CVEs and the confirmation that they are addressed in Percona Server for MySQL 8.4.8-8.1, and that CVE-2025-6965 is not applicable.

However, our main concern is specifically around Percona XtraDB Cluster. Since PXC 8.4.7-7.1 is still based on Percona Server 8.4.7, it appears these fixes are not yet included in Percona XtraDB cluster.

---

<div class="post-metadata">

**Author:** ![Wayne\_Leutwyler](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wayne_leutwyler/32/20829_2.png) [@Wayne\_Leutwyler](https://forums.percona.com/u/Wayne_Leutwyler)\
**Post date:** [April 8, 2026, 5:33pm UTC](https://forums.percona.com/t/ncsc-2026-0032-cves-affecting-pxc-8-4-7-7-1/40348/4 "2026-04-08T17:33:15Z")

</div>

PXC 8.4.8 should be released in the next couple of weeks. I don’t have a solid date that I can share.
