Impact
The vulnerability resides in the Group Replication Plugin of Oracle MySQL Server. It permits a low‑privileged attacker with network access through supported protocols to cause the server to enter a hang or repeatedly crash, abruptly terminating services. No confidential data is disclosed or altered; the effect is limited to availability loss.
Affected Systems
Affected products are Oracle Corporation MySQL Server versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0. The issue is confined to the server component that implements Group Replication.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates moderate severity focused on availability. The EPSS score of <1% indicates a very low likelihood that this vulnerability will be actively exploited in the wild, and it is not listed in CISA KEV, suggesting no known widespread active exploitation. An attacker only needs network reach to the MySQL port and does not require elevated privileges, making exploitation relatively straightforward. Successful exploitation results in a denial‑of‑service condition affecting all clients connected to the compromised instance.
OpenCVE Enrichment