Impact
The vulnerability resides in the Optimizer component of Oracle MySQL Server. A low privileged attacker with network access can trigger repeated server crashes or hangs, resulting in a complete denial of service. The weakness impacts Availability only, with no direct effect on data integrity or confidentiality, as reflected in the CVSS vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.
Affected Systems
Oracle Corporation’s MySQL Server versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0 are affected. All deployments using these releases are vulnerable; version information is provided by Oracle in the referenced CPU.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate severity with significant Availability impact. EPSS data is not available, but the vulnerability is described as easily exploitable, requiring only network connectivity and low‑privileged access. It is not listed in the CISA KEV catalog. Attackers can compromise exposed MySQL endpoints by sending crafted queries that cause the Optimizer module to crash, leading to repeated server restarts.
OpenCVE Enrichment