Impact
The vulnerability resides in the Optimizer component of Oracle MySQL Server and is classified as a resource consumption flaw (CWE‑400). Exploitation can cause the server to hang or repeatedly crash, resulting in a complete denial of service to any application or user relying on the database.
Affected Systems
Oracle MySQL Server versions from 9.0.0 through 9.5.0 are affected. Administrators should verify the exact build and apply the security patch provided by Oracle for these releases.
Risk and Exploitability
With a CVSS base score of 6.5, the vulnerability primarily impacts availability. The EPSS score is below 1 %, indicating a low probability of exploitation, and it is currently not listed in the CISA KEV catalogue. The likely attack vector is a remote, low‑privileged network user sending specially crafted SQL statements over supported protocols, which triggers the optimizer bug and causes the service to crash.
OpenCVE Enrichment