Impact
A vulnerability in the Group Replication Plugin of Oracle MySQL Server allows a low‑privileged attacker with network access through multiple protocols to trigger a hang or recurrent crash of the MySQL Server. An attacker can exploit this flaw to cause a complete denial of service without needing elevated system privileges.
Affected Systems
Oracle MySQL Server versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a moderate severity focused on availability. Attack complexity is low, and the requirement is only network access to the MySQL service. The EPSS score of 0.04% and the absence of the vulnerability from CISA’s KEV catalog suggest that publicly available exploits are uncommon. Nonetheless, the potential for recurring service interruption warrants timely remediation.
OpenCVE Enrichment