Impact
The flaw resides in the Group Replication Plugin of Oracle MySQL Server. An attacker with low privileges and network connectivity can trigger a hang or repeatable crash that takes the server offline. The exploit does not grant further compromise and only corrupts availability, as reflected by the CVSS 3.1 vector AV:N/AC:L/PR:L/C:N/I:N/A:H.
Affected Systems
Oracle MySQL Server 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0 are affected. Any installation of the Group Replication Plugin in these versions can be impacted.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate risk to availability, while the reported EPSS score of 0.0004 (<1%) indicates a very low but nonzero exploitation probability. The vulnerability is not yet in the CISA KEV catalog. Attackers can reach the vulnerable code via the standard MySQL protocols over the network, using a low‑privilege account to execute the crash trigger.
OpenCVE Enrichment