Impact
A vulnerability in the Group Replication Plugin of Oracle MySQL Server allows a low‑privileged attacker with network access through multiple protocols to trigger a hang or recurrent crash of the MySQL Server. An attacker can exploit this flaw to cause a complete denial of service without needing elevated system privileges.
Affected Systems
Oracle MySQL Server versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a moderate severity focused on availability. Attack complexity is low, and the requirement is only network access to the MySQL service. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread publicly available exploits have not yet been reported. Nonetheless, the potential for recurring service interruption warrants timely remediation.
OpenCVE Enrichment