Impact
Vulnerability discovered in the Optimizer component of Oracle MySQL Server allows a high privileged attacker to cause the server to hang or repeatedly crash, resulting in a denial of service. The defect is a form of uncontrolled resource consumption and memory allocation error, as identified by CWE-400 and CWE-770. The impact is limited to availability; there is no direct compromise of confidentiality or integrity.
Affected Systems
Oracle MySQL Server versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0 are affected. Users of these releases should verify their deployments against the Oracle CPU April 2026 advisory.
Risk and Exploitability
The CVSS base score of 4.9 reflects a moderate availability impact. The EPSS score of < 1% indicates a very low yet non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. Successful exploitation requires network access to the MySQL Server and an attacker who possesses high‑level privileges; the most likely attack vector involves sending specially crafted optimizer queries over any of the server’s supported network protocols, a fact that is inferred from the description rather than explicitly stated.
OpenCVE Enrichment