Skip to content

For help, click the link below to get free database assistance or contact our experts for personalized support.

Percona Server for MySQL 8.0.46-39 (2026-10-08)

This release is part of Percona’s MySQL 8.0 End of Life Support – Upgrade to MySQL 8.4 or Stay program. The program provides critical updates and ensures stability for businesses relying on MySQL 8.0 beyond the official EOL.

  • Paying customers can access the full release, including pre-compiled binaries, through the private repository.

  • Community members can build the release from publicly available source code, which is released quarterly.

Upgrading to MySQL 8.4 is recommended, but support for MySQL 8.0 will continue.

Release Information

Percona Server for MySQL 8.0.46-39 builds on MySQL 8.0.46 Community Edition, adding enterprise-grade features and security enhancements from Percona.

Bug fixes

The fixes ported to 8.0 are the following:

  • Bug#39268619: MySQL Router buffered incoming HTTP request bodies and headers without a size limit, so request data could grow without bound before the request was handled. Request bodies are now limited to 32 MiB and headers to 8 KiB. Oversized requests are rejected with an error.

  • Bug#39268692: X Plugin challenge-response authentication accepted malformed MYSQL41 and SHA256_MEMORY responses without first checking that the payload had the expected format. The payloads are now validated before they are decoded.

  • Bug#39268863: X Plugin escaped string literals in generated CRUD statements with backslashes, which did not match sessions that use the NO_BACKSLASH_ESCAPES SQL mode. X Plugin now uses double-quote characters when NO_BACKSLASH_ESCAPES is enabled.

  • Bug#37587555: When a replication channel used an applier user, the privilege check for CREATE and DROP statements failed if the privileges were granted to that user only on a specific database.

  • Bug#39474825: Client BINLOG statement execution with the REPLICATION_APPLIER privilege could follow different privilege-check paths for equivalent events, depending on how the event was encoded.

  • Bug#39282368: Group Replication did not reject some invalid fragmented messages early enough, so invalid fragment sets could reach reassembly. Fragment metadata is now validated before the fragments are accepted.

  • Bug#39234600: XCom client messages received on an external connection could be processed the same way as locally submitted Group Replication messages. Only the expected external client and control messages are now accepted.

  • Bug#39253416: Group Replication message decoders trusted the length fields in received payloads. The payload length is now validated before the data is read.

  • Bug#39138426: The ExtractValue() function could cause the server to exit unexpectedly when it parsed malformed XML declarations, such as <!a/><!b/>.

  • Bug#39253383: Certain malformed replication events were not rejected early enough during processing. The event metadata is now validated earlier.

  • Bug#39254885: Replication could behave unexpectedly when it received a malformed DECIMAL user variable event. The precision, scale, and payload length are now validated.

  • Bug#39254867: A malformed table map event could contain inconsistent column metadata. The metadata bounds are now validated when the event is decoded.

  • Bug#39254896: The replica receiver thread queued events into the relay log without checking that the event type was known. The event type is now validated before the event is queued.

  • Bug#39253491: Malformed GTID dump input could cause excessive processing while the GTID interval data was decoded.

  • Bug#39253359: A replica receiver could report errors when it queued an erroneous fake Rotate event from a source.

  • Bug#39254914: Some events queued directly by the replica I/O thread were not validated in the same way as other replication events.

  • Bug#39282350: A malformed row event with unexpected column count metadata could be handled incorrectly while the relay log was read. The column count is now validated earlier.

  • Bug#39319907: A malformed row event could be handled incorrectly while the replica unpacked the row data. Packed values that exceed the destination column size are now rejected.

  • Bug#39377010: Replication could handle malformed heartbeat events incorrectly instead of reporting a heartbeat validation error.

  • Bug#34233945: Committing or rolling back a detached XA transaction on a server with binary logging disabled could leave the mysql.gtid_executed table inconsistent with @@GLOBAL.GTID_EXECUTED.

  • Bug#38924622: With replica_parallel_type=DATABASE, if the coordinator thread failed to prepare the context for a transaction, the event was not released and the failure was not reported.

  • Bug#39489024: JSON schema validation accepted schemas with cyclic local $ref references, which could exhaust the thread stack. These schemas are now raise an error and are rejected.

  • Bug#33073320: The STATEMENT_DIGEST() and STATEMENT_DIGEST_TEXT() functions could cause memory leaks.

  • Bug#38657550: Dynamic range and index skip scan execution could leave an internal column bitmap pointing to freed memory after an error or an early exit.

  • Bug#39179197: With the subquery_to_derived optimizer switch enabled, a query that used CTEs, a scalar subquery, and repeated references to the same field could cause the server to exit unexpectedly during optimization.

  • Bug#36368181: Condition pushdown could cause an assertion failure when an expression contained both an outer reference through a view and a local reference.

  • Bug#39181231: InnoDB could fail to start when innodb_redo_log_encrypt=ON was set, because a stale value could remain in the data directory path computed during startup.

  • Bug#39244016: InnoDB did not release an internal tablespace mutex in one error path, which could cause a deadlock under high load.

  • Bug#39245844: The clone plugin did not check the destination path of a cloned file received from the donor, so a malicious or compromised donor could make the recipient write files outside the expected directories.

  • Bug#39252316: The clone plugin used a locator index from the donor data without validating it. The value is now checked before use.

  • Bug#39253040: The clone plugin accepted plugin library names from the donor that contained directory separators, such as ../foo.so. These names are now rejected.

  • Bug#39091376: When a DDL operation that built several indexes failed, cleanup was not performed for all index builders, which could leave buffer pool pages fixed.

  • Bug#39245805: The clone recipient could use an invalid data file index from a malformed or out-of-order donor descriptor. The index is now validated before use.

  • Bug#39449066: The OBJECT_INSTANCE_BEGIN and related identity columns in several Performance Schema tables, such as data_locks, metadata_locks, and socket_instances, were based on raw internal memory addresses. These columns are now refactored.

  • Bug#39249507: After the fix for Bug#39129182, CREATE TABLE could fail with a Row size too large (> 8126) error for InnoDB tables that use the DYNAMIC row format and were accepted in earlier releases.

  • Bug#38169053: The server could fail to detect that a tablespace file was in its default location when the data directory was a symbolic link and the tablespace name contained ? or # characters.

  • Bug#37797437: A table maintenance statement, such as CHECK TABLE, could cause an assertion failure if a network error occurred after the operation finished.

Additional Resources